| |||||||||||||
| ID de Prueba: | 1.3.6.1.4.1.25623.1.0.11429 |
| Categoría: | Windows |
| Título: | Windows Messenger is installed |
| Resumen: | Check the version of Microsoft Windows Messenger |
| Descripción: | Overview: This host is installed with Microsoft Windows Messenger and is prone to multiple vulnerabilities. Vulnerability Insight: The flaws are due to - Buffer overflow in Setup ActiveX control (setupbbs.ocx), allows attacker to execute commands via the methods vAddNewsServer or bIsNewsServerConfigured. - An error in 'ActiveX' object allows attacker to disclosure information. - An error in the authentication mechanisms, allows remote attacker to spoof messages. - An error in 'Font' tag and in 'Invite' request allows remote attacker to cause denial of service. Impact: Successful exploitation could allow attackers to bypass certain security restrictions, execute arbitrary code in the context of the browser or cause a denial of service. Impact Level: Application Affected Software/OS: Microsoft MSN Messenger Service 1.x, 2.0.x, 2.2.x, 3.0.x, 3.6.x Microsoft MSN Messenger Service 4.0.x to 4.6.x Fix: No solution or patch is available as of 30th May, 2012. Information regarding this issue will updated once the solution details are available. http://www.microsoft.com/en-us/download/search.aspx?q=MSN%20Messenger References: http://xforce.iss.net/xforce/xfdb/8084 http://xforce.iss.net/xforce/xfdb/8582 http://versions.wikia.com/wiki/MSN_Messenger http://downloads.securityfocus.com/vulnerabilities/exploits/setupbbs.txt |
| Referencia Cruzada: |
BugTraq ID: 4028 BugTraq ID: 4316 BugTraq ID: 4675 BugTraq ID: 4827 BugTraq ID: 668 Common Vulnerability Exposure (CVE) ID: CVE-1999-1484 Bugtraq: 19990924 Several ActiveX Buffer Overruns (Google Search) http://www.securityfocus.com/archive/1/28719 XForce ISS Database: msn-setup-bbs-activex-bo(3310) http://xforce.iss.net/static/3310.php http://www.securityfocus.com/bid/668 Common Vulnerability Exposure (CVE) ID: CVE-2002-0228 Bugtraq: 20020202 MSN Messenger reveals your name to websites (and can reveal email addresses too) (Google Search) http://online.securityfocus.com/archive/1/254021 http://www.iss.net/security_center/static/8084.php http://www.securityfocus.com/bid/4028 Common Vulnerability Exposure (CVE) ID: CVE-2002-0472 Bugtraq: 20020319 Potential vulnerabilities of the Microsoft RVP-based Instant Messaging (Google Search) http://www.securityfocus.com/archive/1/262906 http://www.encode-sec.com/esp0202.pdf http://www.securityfocus.com/bid/4316 http://www.iss.net/security_center/static/8582.php |
| Copyright | This script is Copyright (C) 2003 Xue Yong Zhi |
| Esta es sólo una de 32582 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |
|