Unchecked Buffer in Microsoft MSN Messenger Chat ActiveX Control

A buffer overflow condition exists in Microsoft’s MSN Messenger Chat control that can result in unauthorized code execution.

Ken Pfeil

May 8, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedMay 8, 2002, by eEye Digital Security.

 

VERSION AFFECTED

·        Microsoft MSN Messenger ActiveXChat Control

 

 

DESCRIPTION
Abuffer overflow condition exists in Microsoft’s MSN Messenger Chat controlthat can result in unauthorized code execution. Even if usershaven't installed Messenger, an attacker can call the control from the codebasetag, which would prompt users to install the control with Microsoft'scredentials, because Microsoft signs the OLE custom control (OCX). eEye’sadvisorygives a detailed explanation on this vulnerability.

 

DEMONSTRATION

eEyeDigital Security provided the following example as proof-of-concept:

 

height="523">

 

VENDOR RESPONSE

 

The vendor, Microsoft,has released Security Bulletin MS02-022to address this vulnerability and recommends that affected users apply theappropriate patch listed in the bulletin.

 

CREDIT
Discoveredby Drew Copley and eEye Digital Security.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like