Advertisement
Promo

Security threats Toolkit

MSN Messenger flaw opens back door to hard drive

Michael Kanellos CNET News

Published: 10 Mar 2004 08:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has revealed three new vulnerabilities in its software, including the first to affect MSN Messenger 6.0, and is urging customers to patch their systems now.

Two of the vulnerabilities are considered medium-level risks, while the third presents a medium- to low-level risk, according to security software specialist Symantec and others. Three separate patches to repair the flaws -- which affect different pieces of software -- have been released and are available for download. The identification of the vulnerabilities came on Wednesday as part of Microsoft's regular security bulletin process.

Later, the software giant will also send notices about the Messenger patch through MSN Messenger itself, said Stephen Toulouse, security program manager for the Microsoft Security Response Centre.

The vulnerability in MSN Messenger versions 6.0 and 6.1 could let an attacker view the contents of a victim's hard drive during a chat session with the victim.

Attackers "could view files through MSN Messenger on their computer," Toulouse said. "They can do it, and you are not necessarily aware of what they are doing."

Users who do not block anonymous callers are most vulnerable to the exploit. If anonymous callers are blocked, the attacker has to be identified on the victim's address list. To obtain particular information, such as credit card numbers, attackers have to troll the hard drive, said Toulouse.

Oliver Friedrichs, senior manager for Symantec's security response team, said that victims don't actually have to be in conversation with the attacker. As long as the user permits anonymous callers to send messages, an attacker could come in and peruse Quicken files or other identifiable files that are likely to contain sensitive data. However, most people block that function, so random attacks will probably be rare, he said.

The second medium-level risk could allow a hacker to take over a system by executing Internet Explorer code through a flaw in Outlook 2002.

A computer has to be configured in a particular manner, though, said Toulouse. The user has to set "Outlook Today" as the Outlook home page.

"If you go to Outlook through your inbox, you are protected," he said.

The third flaw allows attackers to instigate a denial-of-service attack against servers running Windows Media Services 4.1. The vulnerability exists because of the way Windows Media Station Service and Windows Media Monitor Service, components of Windows Media Services, handle TCP/IP connections. If an attacker sent a particular sequence of packets to a server running Media Services 4.1, it could interrupt any video streams.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
68 out of 123 people found this useful


Full Talkback thread

1 comment

  1. disabling the messenger is a good idea, but outloo... Kurt Blanchard

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

Post a comment

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters