Threat Monitor
« Back to list
Troj.Clicker.HTML.IFrame.kr
| Aliases: | |
|---|
| Pattern: | 201002151330 |
|---|
| Threat Type | Propagation Methods | Systems Affected | Risk Level |
| | | - Windows NT
- Windows XP
- Windows 2000
- Windows 95/98/ME
- MS-DOS
- Other
| |
Windows Live Messenger is prone to a buffer overflow vulnerability in the Activex Control(msgsc.14.0.8089.726.dll) with the CLSID:B69003B3-C55E-4B48-836C-BC5946FC3B28 on Windows Vista and Windows 7.
The vulnerability exists because it fails to bounds-check user-supplied data. By persuading a victim to visit a specially-crafted Web page that passes an overly long string to the ViewProfile() in the Activex Control, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim.
Affected: Microsoft Windows Live Messenger 2009
Back to Top