First published: Wed May 29 2002(Updated: )
Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Messenger | =4.6 | |
Microsoft MSN Messenger | =4.6 | |
Microsoft MSN Messenger | ||
Microsoft Messenger | =4.5 | |
Microsoft MSN Messenger | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0155 is considered highly critical due to the potential for remote code execution.
To fix CVE-2002-0155, ensure you update to the latest version of Microsoft MSN Messenger or the MSN Chat Control.
CVE-2002-0155 affects Microsoft MSN Messenger versions 4.5 and 4.6, as well as the MSN Messenger Service for Exchange.
Yes, CVE-2002-0155 can be exploited remotely by sending a specially crafted ResDLL parameter.
CVE-2002-0155 is a buffer overflow vulnerability that allows attackers to execute arbitrary code.