On last.fm: Lollapalooza 2009
BNET Business Network:
BNET
TechRepublic
ZDNet

September 1st, 2009

Microsoft to push 'mandatory' Live Messenger security patch

Posted by Ryan Naraine @ 10:23 am

Categories: Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Hackers, Locally Running Web Servers, Microsoft, Passwords, Patch Watch, Responsible disclosure, Spam and Phishing, Spyware and Adware, Vulnerability research, Windows Vista

Tags: Microsoft Windows Live Messenger, Microsoft Windows Live, Microsoft Corp., Microsoft Windows, Operating Systems, Security, Software, Ryan Naraine

Microsoft plans to force a mandatory Windows Live Messenger upgrade later this month to fix a security problem that exposes Windows users to remote code execution attacks.

The security issue, caused by an extra character in the Microsoft Active Template Library (ATL), affects users of Windows Live Messenger 8.1 and 8.5 on Windows XP, Windows Vista and Windows Server 2008.

From Microsoft’s Messenger Says blog:

The upgrade process will take place in a phased approach over the next several weeks:

First Phase, Optional Upgrade:
The optional upgrade will happen in two stages:
Starting Aug. 25, customers using versions 8.1 or 8.5 were asked to upgrade their client.
Starting early Oct., all customers using versions 14.0 (but not the latest release 14.0.8089) will be asked to upgrade their client.
The upgrade at this time is optional. Customers who haven’t upgraded during the optional phase will be required to do so during the second phase.

Second Phase, Mandatory Upgrade:
The mandatory upgrade will happen in three stages:
Starting mid-Sept., all customers using Messenger 8.1 or 8.5 will be required to upgrade their version of Windows Live Messenger.
Starting late Oct., all customers using Messenger 14.0 will be required to upgrade their version of Windows Live Messenger.
To ensure that we are protecting customers, those who do not administer the upgrade will not be able to sign in to Messenger after this time.

More details on the Microsoft ATL vulnerabilities can be found in this security advisory.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 9 Talkback(s)
Of course...
...patc hes are not indicative of poor security. Macs are insecure because they are a small target and have not really had to do any defending. This huge attack vector has made MS the butt of jokes and attacks, but has hardened them far more than apple.... (Read the rest)
Posted by: melekali Posted on: 09/03/09 You are currently: a Guest | | Terms of Use
More details on the Microsoft ATL vulnerabilities  gertruded | 09/01/09
Existence of security patches means an OS isn't secure?  NonZealot | 09/01/09
He cannot, because there is no link between security patches  Lerianis10 | 09/01/09
That's the line you push for every OS X patch  Fred Fredrickson | 09/02/09
RE: Microsoft to push 'mandatory' Live Messenger security patch  djmik | 09/01/09
Live Messenger is meant for home use  Lerianis10 | 09/01/09
RE: Microsoft to push 'mandatory' Live Messenger security patch  Laura42773@... | 09/03/09
Interesting Approach  melekali | 09/03/09
Of course...  melekali | 09/03/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More