Yahoo Messenger zero-day exploits on the loose
'Extremely critical' bugs let attackers snatch control of Windows PCs via IM
Computerworld - Shortly after eEye Digital Security notified Yahoo Inc. yesterday that the portal's Messenger IM client was vulnerable to attack, a researcher fingered two ActiveX controls as flawed and posted exploit code that can be used to hijack Windows machines.
Although eEye's advisory was vague about details -- it said Messenger's Webcam ActiveX control was at fault -- the researcher laid all bare on the full-disclosure list.
The researcher, who went by the name "Danny," cited "45 minutes of fuzzing!" in a post yesterday about the flaw. In a follow-up today, Danny published a second exploit. "This affects the viewer ywcvwr.dll with yahoo messenger," he said.
Aliso Viejo, Calif.-based eEye called the Yahoo Messenger bugs serious. "ActiveX remote code execution vulnerabilities have very high impacts since the source of the malicious payload can be any site," the security vendor said. "An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with administrator credentials."
Most Windows XP users run in administrator mode.
Danish vulnerability tracker Secunia ApS rated the Messenger bugs as "extremely critical" -- its highest-possible threat ranking.
Until Yahoo provides a patch, eEye said the only work-around defense is to set the kill-bit for the two Yahoo ActiveX controls. However, because that involves manually editing the Windows registry, it's not a tactic most users will feel comfortable doing. Microsoft Corp., which in the past has recommended kill-bitting to temporarily protect users against vulnerabilities in Internet Explorer and its other software, has offered a set of technical instructions on setting kill bits.
Yahoo has not yet posted a fix for the flaws to its security update page. The last Messenger bug, also because of a vulnerable ActiveX control, was fixed in April.
Read more about Security in Computerworld's Security Topic Center.
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts