Microsoft MSN ActiveX Object Information Disclosure Vulnerability
BID:4028
Info
Microsoft MSN ActiveX Object Information Disclosure Vulnerability
| Bugtraq ID: | 4028 |
| Class: | Design Error |
| CVE: |
CVE-2002-0228 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Discovered by Richard Burton <[email protected]>. |
| Vulnerable: |
Microsoft MSN Messenger Service 4.6 Microsoft MSN Messenger Service 4.5 Microsoft MSN Messenger Service 4.0 Microsoft MSN Messenger Service 3.0 Microsoft MSN Messenger Service 2.2 |
| Not Vulnerable: | |
Discussion
Microsoft MSN ActiveX Object Information Disclosure Vulnerability
Microsoft's MSN Messenger is a popular instant messenger application for the Window's family of operating systems. It is based on the Passport system, and users are uniquely identified by an email address.
Some versions of MSN Messenger expose the current user's display name and contact list through an ActiveX control available to arbitrary javascript programs. In the absense of a display name, the user's email address is revealed. Malicious web pages may use this to gather personal information or track a user through multiple domains.
Additional information is available to trusted domains stored in the registry. By default, no domains are defined here, although several Microsoft sites are trusted regardless.
Microsoft's MSN Messenger is a popular instant messenger application for the Window's family of operating systems. It is based on the Passport system, and users are uniquely identified by an email address.
Some versions of MSN Messenger expose the current user's display name and contact list through an ActiveX control available to arbitrary javascript programs. In the absense of a display name, the user's email address is revealed. Malicious web pages may use this to gather personal information or track a user through multiple domains.
Additional information is available to trusted domains stored in the registry. By default, no domains are defined here, although several Microsoft sites are trusted regardless.
Exploit / POC
Microsoft MSN ActiveX Object Information Disclosure Vulnerability
No exploit code is required to take advantage of this issue.
An example page has been made available by Richard Burton <[email protected]>:
http://raburton.members.easyspace.com/msn/
No exploit code is required to take advantage of this issue.
An example page has been made available by Richard Burton <[email protected]>:
http://raburton.members.easyspace.com/msn/
Solution / Fix
Microsoft MSN ActiveX Object Information Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft MSN ActiveX Object Information Disclosure Vulnerability
References:
References:
- MSN Messenger Homepage (Microsoft)
- MSN Messenger Privacy (Richard Burton
)