RETIRED: Windows Live Messenger 'ViewProfile()' Method ActiveX Control Buffer Overflow Vulnerability
BID:37680
Info
RETIRED: Windows Live Messenger 'ViewProfile()' Method ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 37680 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 08 2010 12:00AM |
| Updated: | Jan 12 2010 08:41AM |
| Credit: | HACKATTACK IT Security GmbH and Natal Networks Inc. |
| Vulnerable: |
Microsoft Windows Live Messenger 2009 0 |
| Not Vulnerable: | |
Discussion
RETIRED: Windows Live Messenger 'ViewProfile()' Method ActiveX Control Buffer Overflow Vulnerability
Windows Live Messenger is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successful exploits allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Windows Live Messenger 2009 on Windows Vista and 7 is vulnerable; other versions may also be affected.
NOTE: The BID is being retired. The issue is not exploitable because the control is not safe for scripting.
Windows Live Messenger is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successful exploits allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Windows Live Messenger 2009 on Windows Vista and 7 is vulnerable; other versions may also be affected.
NOTE: The BID is being retired. The issue is not exploitable because the control is not safe for scripting.
Exploit / POC
RETIRED: Windows Live Messenger 'ViewProfile()' Method ActiveX Control Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
RETIRED: Windows Live Messenger 'ViewProfile()' Method ActiveX Control Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Windows Live Messenger 'ViewProfile()' Method ActiveX Control Buffer Overflow Vulnerability
References:
References: