vendor:
Yahoo Messenger
by:
Unknown
9
CVSS
CRITICAL
Remote Code Execution
CWE
Product Name: Yahoo Messenger
Affected Version From: Unknown
Affected Version To: Latest version tested
Patch Exists: NO
Related CWE:
CPE: cpe:2.3:a:yahoo:messenger:*:*:*:*:*:*:*:*
Platforms Tested: Windows
2007
Remote Code Execution in ywcvwr.dll with Yahoo Messenger
This exploit affects the viewer ywcvwr.dll with Yahoo Messenger. The latest version has been tested. The exploit leverages a fixed bug in the last post. The exploit allows an attacker to execute arbitrary code on the target system. The link to the exploit details can be found at http://www.informationweek.com/news/showArticle.jhtml?articleID=199901856.
Mitigation:
Apply the latest patches and updates from Yahoo Messenger. Avoid opening or accepting files from untrusted sources.