MS.Live.Messenger.Illegal.Access

Last Updated DateSep 02, 2008
Release DateFeb 15, 2008
SeverityMedium
ImpactInformation Disclosure: remote attackers can gain sensitive information from vulnerable systems.
DescriptionThis indicates an attempt to exploit multiple information disclosure vulnerabilities in Microsoft Windows Live Messenger.

With the information that is disclosed, a malicious attacker can control the local Live Messenger. The exploit also reveals personal information from Live Messenger and makes it possible to transfer local audio and video information to a remote location.
Affected ProductsWindows Messenger 4.7
Windows Messenger 5.1
Recommended ActionsRefer to the vendor's web site for suggested workaround.
http://www.microsoft.com/technet/security/Bulletin/08-050.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0082
Microsoft Bulletin IDMS08-050   http://www.microsoft.com/technet/security/Bulletin/ms08-050.mspx
Reference: VID-15397