|
Product:
Windows Live Messenger 2009 (Build 14.0.8089.726)
********************************************************************************
Vulnerability:
ActiveX - Denial of Service
********************************************************************************
Discussion:
Vulnerability is in Activex Control(msgsc.14.0.8089.726.dll)
Sending a string to ViewProfile() , cause a crash on msnmsgr.exe
*must be signed in Msn Messenger account for triggerin the vulnerability.
********************************************************************************
Vulnerable:
Windows Live Messenger 2009 on Windows Vista
Windows Live Messenger 2009 on Windows 7
Not Vulnerable:
Windows Live Messenger 2009 on Windows XP
Credits:
HACKATTACK IT SECURITY GmbH
Penetration Testing in Deutschland - =D6sterreich - Schweiz
www.hackattack.com
and
Natal Networks Inc.
Vulnerability Discovery, Penetration Testing, IT Security Consulting
www.natalnetworks.com
********************************************************************************
Original Advisory
www.hackattack.com
www.natalnetworks.com
********************************************************************************
PoC .wsf script:
'works on vista and windows7