An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5995 | vdb entry signature |
http://www.vupen.com/english/advisories/2008/2354 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-225A.html | third party advisory us government resource |
http://marc.info/?l=bugtraq&m=121915960406986&w=2 | vendor advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-050 | vendor advisory |
http://www.securityfocus.com/bid/30551 | vdb entry |
http://www.securityfocus.com/archive/1/495467/100/0/threaded | mailing list |
http://secunia.com/advisories/31446 | third party advisory vendor advisory |
http://www.securitytracker.com/id?1020681 | vdb entry |