Microsoft MSN Chat Control Remote Buffer Overflow Vulnerability
BID:4707
Info
Microsoft MSN Chat Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 4707 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2002 12:00AM |
| Updated: | May 08 2002 12:00AM |
| Credit: | Credited to Drew Copley. |
| Vulnerable: |
Microsoft MSN Chat Control |
| Not Vulnerable: | |
Discussion
Microsoft MSN Chat Control Remote Buffer Overflow Vulnerability
The Microsoft MSN Chat Control is an ActiveX object used to provide chat functionality. It is included by default with a number of Microsoft products, including recent versions of MSN Messenger.
The MSN Chat ActiveX control is vulnerable to a buffer overflow. Exploitation of this vulnerability can result in the execution of arbitrary code. This vulnerability may be exploited when a user views a web page or HTML formatted email.
The Microsoft MSN Chat Control is an ActiveX object used to provide chat functionality. It is included by default with a number of Microsoft products, including recent versions of MSN Messenger.
The MSN Chat ActiveX control is vulnerable to a buffer overflow. Exploitation of this vulnerability can result in the execution of arbitrary code. This vulnerability may be exploited when a user views a web page or HTML formatted email.
Exploit / POC
Microsoft MSN Chat Control Remote Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft MSN Chat Control Remote Buffer Overflow Vulnerability
Solution:
Downloading current versions from Microsoft of MSN Instant Messenger and Exchange Instant Messenger will install the patched control.
The original Microsoft fixes did not protect against reintroduction of a vulnerable MSN Chat control.
Microsoft has released a new fix which corrects this issue:
Microsoft MSN Chat Control
Solution:
Downloading current versions from Microsoft of MSN Instant Messenger and Exchange Instant Messenger will install the patched control.
The original Microsoft fixes did not protect against reintroduction of a vulnerable MSN Chat control.
Microsoft has released a new fix which corrects this issue:
Microsoft MSN Chat Control
-
Microsoft MSNChatSecFix.exe
Updated Microsoft fix.
http://download.microsoft.com/download/chat/Patch/4.2/WIN98MeXP/EN-US/ MSNChatSecFix.exe
References
Microsoft MSN Chat Control Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-022 (Microsoft)