- Recommend:
- 0 Comments
IE Bug Opens New Hole in MSN Messenger
Bug-hunters say a second, more dangerous flaw could invite worms, PC invaders.
Shortly after Microsoft admitted MSN Messenger has a bug that could disclose the names and e-mail addresses on a user's contact list, the company is being confronted with what seems to be a bigger hole.
A malicious Web site operator can hijack a user's MSN Messenger instant messaging application and perform all tasks, including sending messages and personal files, bug-hunters claimed this weekend. The charge was posted in a bulletin on the Bugtraq mailing list on Saturday, and a warning issued by security software firm Finjan Software on Sunday.
To take over a user's MSN Messenger program, an attacker has to exploit a known hole in Internet Explorer by sending specially crafted code in an HTML e-mail or directing the user to a Web site that contains that code, according to the security advisories.
The Internet Explorer hole, known as the Document.Open() bug, was first discovered in December.
Microsoft has yet to plug the hole. A patch was initially published late last week, only to be removed from the Windows Update service hours later, according to a message on Tom Gilder's Web site. Gilder wrote the Bugtraq bulletin. Microsoft representatives said no one at the software company was available to comment on the latest bug report.
Security Concern
Security researchers at Finjan expect the flaw to be exploited by many. The firm states that an "MSN Messenger worm" could be written based on this vulnerability. Systems with Internet Explorer 5.5. and 6.0 and MSN Messenger 2.21 and above installed are vulnerable, according to Finjan.
Users can protect themselves by disabling active scripting in Internet Explorer or by not using MSN Messenger, which is software offered for free by Microsoft and is a standard part of Windows XP.
Microsoft on Friday confirmed that MSN Messenger has a bug that could disclose the names and e-mail addresses on a user's contact list to malicious Web site operators.
The company declared the problem 'low-risk,' and is working on an update for MSN Messenger to fix that flaw. Microsoft representatives suggest users solve the problem by downloading and installing the update when it becomes available. This flaw was also initially mentioned in an alert posted to the Bugtraq security e-mail list on February 2.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Bugs and Fixes: Patch New Cracks in Microsoft Software
- Bugs and Fixes: Serious Security Holes in Internet Explorer
- Gmail Bug Deletes E-Mails for 150,000 Users
- Microsoft Issues Emergency Security Patch For IE
- Microsoft's Fix for Outlook's 'General Failure' Error for E-Mail Links
- Excel, Movie Maker Flaws Fixed by Microsoft
- Critical Zero-Day Flaw Opens Holes in IE 6 and 7
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.

















