Block MSN Messenger Live 8
| Check Point Reference: | CPAI-2006-143 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | SmartDefense Research Center | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? MSN Messenger Live 8 | ||
| Vulnerability Description Windows Live Messenger, formerly and still commonly known as MSN Messenger or MSN, is a freeware instant messaging client for Windows XP and Windows Vista. It is part of Microsoft's Windows Live set of online services. Released on June 19, 2006, MSN Messenger Live 8 has many features including offline conversations, the possibility to share files with other users and more. SmartDefense allows you to block MSN Messenger Live 8. |
||
|
Vulnerability Details Instant messaging applications may risk an organization's security in the following ways: 1. Vulnerabilities in IM applications could be exploited to compromise a user's system. 2. An important capability of IM is file transfer that could be exploited by worms to infect a user's system. 3. Using voice data along with file transfers may result in excessive bandwidth utilization. |
Protection Overview
The Update enables the HTTP Worm Catcher to detect and block MSN Messenger Live 8 based on pre-defined worm signatures. Please note that this update does not block MSN Messenger Live 8 Beta.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on November 30, 2006 includes the following protections:
Novell eDirectory 'evtFilteredMonitorEventsRequest' Vulnerability (CPAI-2006-137)
Microsoft NetWare Client Service Remote Code Execution Vulnerability (MS06-066) - CPAI-2006-138
Microsoft Workstation Service Buffer Overflow Vulnerability (MS06-070) - CPAI-2006-139
Microsoft XML Remote Code Execution Vulnerability (MS06-071) - CPAI-2006-140
Visual Studio WMI Code Execution Vulnerability (CPAI-2006-141)
Microsoft Agent Remote Code Execution Vulnerability (MS06-068) - CPAI-32006-142
Block MSN Messenger Live 8 (CPAI-2006-143)
AOL Nullsoft Winamp Ultravox Heap Overflow Vulnerability (CPAI-2006-144)