Update Protection against Messenger Information Disclosure Vulnerability (MS08-050)
| Check Point Reference: | CPAI-2008-120 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Bulletin MS08-050 | |
| Industry Reference(s): | CVE-2008-0082 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Windows Messenger 4.7 Windows Messenger 5.1 MSN Messenger 7.0.0820 Windows Live Messenger 8.1 Windows Live Messenger 8.5 | ||
| Vulnerability Description An information disclosure vulnerability exists in Windows Messenger, MSN Messenger, and Windows Live Messenger, which are popular instant messaging clients for Microsoft Windows. A remote attacker can exploit this issue to take complete control over a victim’s messenger ID. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS08-050 |
|
|
Vulnerability Details The vulnerability is caused by an ActiveX control that is marked safe, allowing developers to script it. To trigger this issue, an attacker may create a malicious web page that will exploit this vulnerability. Successful exploitation may allow the attacker to view and change the victim's messenger information (such as state and contact list) and to take complete control over a user's ID. |
Protection Overview
By enabling this protection, SmartDefense will detect and block the vulnerable ActiveX Control. Depending on the traffic mix, activating this protection may result in performance degradation.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.