This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Msn Messenger 7.x And Prior - Vuln Unpatched

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/26570/
Last Update: 2007-08-29
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Microsoft MSN Messenger 6.x, 7.x
…The vulnerability is reported in version 7.x. Other versions may also be affected.
Solution: No fix is available for 7.x versions and prior. Users are encouraged to upgrade to Windows Live Messenger 8.1 or later, which is not affected by the vulnerability…

> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2931

Windows Live Messenger 8.1 download
- http://preview.tinyurl.com/38t8r5

.
FYI…

- http://messengersays.spaces.live.com/Blog/…E%2129167.entry
September 12, 2007 - "…We will soon configure the service such that any user on Windows XP or later system has to use Windows Live Messenger 8.1. When a user using an older version of Messenger tries to login, the client will help the user with a mandatory upgrade to Messenger 8.1…
Do users have to upgrade?
Yes, once a user has been given a mandatory upgrade notice, they will have to install Windows Live Messenger 8.1. Most users have been given an optional upgrade notice since January 2007.
I am not seeing a mandatory upgrade right now and I am running a bad version of the client, why?
The Messenger network uses a rolling upgrade mechanism across the network. It will take several days to get a mandatory upgrade and new bits to all users.
What can users do now to protect themselves sooner?
Users running Windows Live Messenger 8.1 do not need to take action. Users running earlier versions of Messenger should visit http://messenger.live.com and install Windows Live Messenger 8.1…"

.