Vulnerability Description
A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows Live Messenger | 2009 |
| Microsoft | Windows 7 | All versions |
| Microsoft | Windows Vista | All versions |
References
- http://www.securityfocus.com/archive/1/508811/100/0/threaded
- http://www.securityfocus.com/bid/37680Exploit
- http://www.securityfocus.com/archive/1/508811/100/0/threaded
- http://www.securityfocus.com/bid/37680Exploit
FAQ
What is CVE-2010-0278?
CVE-2010-0278 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (m...
How severe is CVE-2010-0278?
CVE-2010-0278 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0278?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows Live Messenger, Microsoft Windows 7, Microsoft Windows Vista.