Vulnerability Note VU#575892

Buffer overflow in Microsoft Messenger Service

Overview

There is a buffer overflow in the Microsoft Windows Messenger service that could allow an attacker to execute arbitrary code on most recent versions of Microsoft Windows.

I. Description

There is a buffer overflow vulnerability in the Microsoft Windows Messenger service. This could allow an attacker to execute arbitrary code with System privileges. Microsoft recommends immediately disabling the Messenger service and evaluating the need for the patch. For more information, see Microsoft Security Bulletin MS03-043. This vulnerability affects virtually all recent versions of Windows with the exception of Microsoft Windows Millennium Edition. On Windows Server 2003, the Messenger service is disabled by default; however, if it is enabled the server is vulnerable to compromise.

II. Impact

An attacker can run arbitrary code with Local System privileges.

III. Solution

Disable the Windows messenger service and evaluate the need to apply the patch. to disable the Messenger service, follow these steps as provided by Microsoft: