CVE-2002-0228: Medium severity Microsoft MSN Messenger vulnerability
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0228?
CVE-2002-0228 has a moderate severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2002-0228?
To fix CVE-2002-0228, upgrade to a newer version of Microsoft MSN Messenger that is not affected.
What versions of MSN Messenger are affected by CVE-2002-0228?
CVE-2002-0228 affects MSN Messenger versions 2.2, 3.0, 4.0, 4.5, and 4.6.
What kind of attacks can exploit CVE-2002-0228?
CVE-2002-0228 can be exploited through a malicious script that utilizes ActiveX to access sensitive user information.
Is user interaction required to exploit CVE-2002-0228?
Yes, user interaction is required as the exploit relies on the victim visiting a specially crafted site.