vendor:
Windows Live Messenger 2009
by:
HACKATTACK IT SECURITY GmbH and Natal Networks Inc.
7,5
CVSS
HIGH
ActiveX - Denial of Service
20
CWE
Product Name: Windows Live Messenger 2009
Affected Version From: Windows Live Messenger 2009 on Windows Vista and Windows 7
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: a:microsoft:windows_live_messenger
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista, Windows 7
2009
ActiveX – Denial of Service
Vulnerability is in Activex Control(msgsc.14.0.8089.726.dll) Sending a string to ViewProfile() , cause a crash on msnmsgr.exe *must be signed in Msn Messenger account for triggerin the vulnerability.
Mitigation:
Update to the latest version of Windows Live Messenger 2009