Unchecked Buffer in Microsoft MSN Messenger Chat ActiveX Control
A buffer overflow condition exists in Microsoft’s MSN Messenger Chat control that can result in unauthorized code execution.
May 8, 2002
ReportedMay 8, 2002, by eEye Digital Security.
VERSION AFFECTED
· Microsoft MSN Messenger ActiveXChat Control
DESCRIPTION
Abuffer overflow condition exists in Microsoft’s MSN Messenger Chat controlthat can result in unauthorized code execution. Even if usershaven't installed Messenger, an attacker can call the control from the codebasetag, which would prompt users to install the control with Microsoft'scredentials, because Microsoft signs the OLE custom control (OCX). eEye’sadvisorygives a detailed explanation on this vulnerability.
DEMONSTRATION
eEyeDigital Security provided the following example as proof-of-concept:
height="523">
VENDOR RESPONSE
The vendor, Microsoft,has released Security Bulletin MS02-022to address this vulnerability and recommends that affected users apply theappropriate patch listed in the bulletin.
CREDIT
Discoveredby Drew Copley and eEye Digital Security.
Read more about:
MicrosoftAbout the Author
You May Also Like