Vulnerabilities > CVE-2010-0278 - Buffer Overflow vulnerability in Microsoft Windows Live Messenger 2009

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
microsoft
exploit available

Summary

A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1
OS
Microsoft
2

Exploit-Db

descriptionWindows Live Messenger 2009 ActiveX DoS Vulnerability. CVE-2010-0278. Dos exploit for windows platform
idEDB-ID:11070
last seen2016-02-01
modified2010-01-08
published2010-01-08
reporterHACKATTACK IT SECURITY GmbH
sourcehttps://www.exploit-db.com/download/11070/
titleWindows Live Messenger 2009 - ActiveX DoS Vulnerability