On CHOW: Can girls use the guys' bathroom?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Michael Kanellos
Posted on ZDNet News: Mar 9, 2004 9:28:00 PM

Microsoft has revealed three new vulnerabilities in its software, including the first to affect MSN Messenger 6.0, and is urging customers to patch their systems now.

Two of the vulnerabilities are considered medium-level risks, while the third presents a medium- to low-level risk, according to security software specialist Symantec and others. Three separate patches to repair the flaws--which affect different pieces of software--have been released and are available for download. The identification of the vulnerabilities came Tuesday as part of Microsoft's regular security bulletin process.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Later, the software giant will also send notices about the Messenger patch through MSN Messenger itself, said Stephen Toulouse, security program manager for the Microsoft Security Response Center.

The vulnerability in MSN Messenger versions 6.0 and 6.1 could let an attacker view the contents of a victim's hard drive during a chat session with the victim.

Attackers "could view files through MSN Messenger on their computer," Toulouse said. "They can do it, and you are not necessarily aware of what they are doing."

Users who do not block anonymous callers are most vulnerable to the exploit. If anonymous callers are blocked, the attacker has to be identified on the victim's address list. To obtain particular information, such as credit card numbers, attackers have to troll the hard drive, said Toulouse.

Oliver Friedrichs, senior manager for Symantec's security response team, said that victims don't actually have to be in conversation with the attacker. As long as the user permits anonymous callers to send messages, an attacker could come in and peruse Quicken files or other identifiable files that could likely contain sensitive data. However, most people block that function, so random attacks will likely be rare, he said.

The second medium-level risk could allow a hacker to take over a system by executing Internet Explorer code through a flaw in Outlook 2002.

A computer has to be configured in a particular manner, though, said Toulouse. The user has to set "Outlook Today" as the Outlook home page.

"If you go to Outlook through your in-box, you are protected," he said.

The third flaw allows attackers to instigate a denial-of-service attack against servers running Windows Media Services 4.1. The vulnerability exists because of the way Windows Media Station Service and Windows Media Monitor Service, components of Windows Media Services, handle TCP/IP connections. If an attacker sent a particular sequence of packets to a server running Media Services 4.1, it could interrupt any video streams.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 58 Talkback(s)
actually,
i don't use linux much at all. my linux experience is fairly limited compared to my windows experience. I say good things about linux, because i see good things from it. everyone has different needs... (Read the rest)
Posted by: ryusen Posted on: 03/11/04 You are currently: a Guest | | Terms of Use
50 billion can not stop the negative security news.  DonnieBoy | 03/09/04
Faster Than Windows ???  nikoli | 03/09/04
Longhorn on the way?  Monkey_MCSE | 03/09/04
Longhorn on the way?  seosamh_z | 03/09/04
Look how fast Linux is improving.  DonnieBoy | 03/09/04
applications compatible with XP ha ha  hipparchus | 03/10/04
Integration makes them part of OS  Sunny Jalolly | 03/09/04
Re: "as user friendly as XP": . . . Your priorities are bass ackwards !!!  Plain Logic | 03/09/04
In 1-2 years peope will be surprised  michael-t | 03/09/04
Groan, hardly a trivial fault with messenger then  hipparchus | 03/10/04
Re: Faster Than Windows  wadeprater | 03/09/04
Sco  voska | 03/10/04
Sco Lies!!!!  nucrash | 03/10/04
Re: Sco Lies!!!!  jones_jj | 03/10/04
Actually they are a serious problem  Rick_K | 03/09/04
3-5 years  hipparchus | 03/10/04
It's common sense  voska | 03/10/04
50 billion can not stop the negative security news  seosamh_z | 03/09/04
Security and 200,000 Software Assurance Customers who may or may not renew.  rinaldo | 03/10/04
MCSE'S ARE FOR MONKEYS  FreeBSD | 03/09/04
works for me  Monkey_MCSE | 03/09/04
True, there is good money to be made keeping Windows running.  DonnieBoy | 03/09/04
You're right  Chad_z | 03/09/04
Hey, now  Chad_z | 03/09/04
real cute!!!  ryusen | 03/09/04
The article said "notices"...  Confused by religion | 03/09/04
Actually ZZ may have a point  Squawkbox | 03/09/04
Not to worry.  DragonBRockin | 03/10/04
perhaps...  ryusen | 03/10/04
I can relate.  DragonBRockin | 03/10/04
The fact of the matter is...  theace18 | 03/09/04
The reviews seem to be working.  joseb_z | 03/09/04
MSN Messenger with XP, downloadable one  hipparchus | 03/10/04
They Do  Test Subject | 03/10/04
as us geeks read this...  cchenoweth | 03/09/04
I'm an unhappy microsoft customer  hipparchus | 03/10/04
and the vulnerability causes spam and viruses blocking the net for all os  hipparchus | 03/10/04
Take head out of sand  voska | 03/10/04
why does a media player need to accespt INCOMMING connectons  JWatson77 | 03/09/04
So it can be periodically queried to find out what it has done  Taz_z | 03/10/04
"Windows Media Station Service " is server side  jfrankcarr | 03/10/04
MSN Instant Messenger NOT part of Windows OS.  DragonBRockin | 03/10/04
re: two points  ryusen | 03/10/04
Agreed but...  DragonBRockin | 03/10/04
actually,  ryusen | 03/11/04
WRONG !!! Messenger on my machine is MSN Messenger  hipparchus | 03/10/04
Better look again Dude!  DragonBRockin | 03/10/04
And also.  DragonBRockin | 03/10/04
HUH??  jones_jj | 03/10/04
Excellent Post!  DragonBRockin | 03/10/04
MS Longhorn  dogman_z | 03/10/04
I disagree  nucrash | 03/10/04
Age does not equal maturity  RamaBrooks | 03/10/04
Good Point  middle of nowhere | 03/10/04
Nothing New  bit_rot | 03/10/04
Partially Right  bit_rot | 03/10/04
Re: Partially Right  jones_jj | 03/10/04
contention:  ryusen | 03/10/04

What do you think?

advertisement
Click Here
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here