vendor:
Windows Live Messenger
by:
TheLeader
7,8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Windows Live Messenger
Affected Version From: 14.0.8117 and prior
Affected Version To: 14.0.8117 and prior
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:windows_live_messenger
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x86
2010
Windows Live Messenger <= 14.0.8117 animation remote Denial of Service
Windows Live Messenger is prone to a Denial of Service attack. By sending specially crafted messages that contain a large number of animations ('Smileys'), it is possible to make WLM consume large amounts of memory and CPU while it attempts to render the animated images, causing it to stop responding.
Mitigation:
Ensure that the Windows Live Messenger application is up to date with the latest security patches.