Microsoft has updated Security Bulletin MS05-022 and re-released it to address the fact that the original update included a link to the older, flawed software. This is a critical vulnerability in MSN Messenger that could allow an attacker to take control of a user’s desktop. The hole takes advantage of a “GIF file validation error in MSN Messenger 6.2 that allows remote attackers in a user’s contact list to execute arbitrary code via a GIF image with an improper height and width,” according to the Homeland Security Common Vulnerabilities and Exposure’s site.
But don’t be too alarmed. This vulnerability was fixed in April, 2005. The major change that required a re-release of the bulletin was to fix the fact that the bulletin itself contained a link to download MSN Messenger 6.2 and other, older versions of the instant messaging client. It also listed as affected software versions of Windows Live Messenger (including 8). But folks wanting to download Microsoft’s instant messenger client will now be shifted to the current version of Windows Live Messenger 9, which is not listed as affected software.
However, if you have yet to upgrade your IM client from MSN Messenger 6.2, perhaps the time has come.
Visit the Microsoft Subnet web site for more news, blogs, podcasts. Also see:
Microsoft to cut 5,000 as income fallsEU slaps Microsoft (again) for antitrust over IE bundled with WindowsWindows 7: the untold story of how the enterprise gets snubbedWindows 7 beta wrecks your MP3 files (already has a patch)Subscribe to all Microsoft Subnet bloggers.bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)Sign up for the




