MS.Windows.Messenger.Service.Buffer.Overflow

description-logoDescription

This indicates an attack attempt against a buffer-overflow vulnerability in Microsoft Windows Messenger service.
The vulnerability is a result of insufficient bounds checking of messages before they are passed to an internal buffer. This may lead to a denial of service or the execution of arbitrary code on the victim machine, and even full system compromise.

affected-products-logoAffected Products

Microsoft Windows 2000
Microsoft Windows NT
Microsoft Windows Server 2003
Microsoft Windows XP

Impact logoImpact

Denial of service.
System compromise: Remote code execution.

recomended-action-logoRecommended Actions

Apply the patch supplied by the vendor:
http://www.microsoft.com/technet/security/Bulletin/MS03-043.mspx

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

References

1