Skip to main content

Microsoft Windows Messenger Information Disclosure Vulnerability( 13 August 2008 )

Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5261 Views

RISK: Medium Risk

An information disclosure vulnerability exists in supported versions of Windows Messenger. Scripting of a particular ActiveX control, Messenger.UIAutomation.1, could allow information disclosure from these programs in the context of the logged-on user. An attacker could change state, get contact information, and initiate audio and video chat sessions without the knowledge of the logged-on user. An attacker could also capture the user's logon ID and remotely log on to the user's Messenger client as that user.