Yahoo Messenger hit with ninth zero-day exploit

The latest exploit on the Web can force-feed a malicious file to IM users

Attack code that targets Yahoo Messenger has been published on the Internet, a security researcher warned Wednesday, marking the ninth exploit aimed at the popular instant messaging software so far this year.

In a posting to the milw0rm.com Web site, someone identified as "shinnai" disclosed malicious Visual Basic code that allegedly lets attackers feed any file to users of the latest version of Messenger. The exploit code successfully executes on a fully-patched PC running Windows XP SP2, shinnai said, although the effect depends on the security settings of Internet Explorer (IE).

According to an e-mail alert from nCircle Network Security, hackers armed with the exploit could force-feed malware such as a Trojan horse to vulnerable users. It was nCircle that pegged the latest zero-day threat against Messenger as No. 9 for the year.

IE's security, however, can mitigate an attack. Users running the newer IE 7 with default security settings will probably be protected.

"This latest exploit is another data point in the strong trend toward IM client attacks," said Andrew Storms, nCircle's director of security operations. "IM vendors jockeying for market share are trying to lure new users with new features that also open up new risks to end users."

Storms was referring to the rash of instant messaging program flaws that have been uncovered in recent months. Yahoo Messenger, for example, has been patched several times this summer, while Microsoft decided less than a week ago on a mandatory upgrade that meant all users of its MSN Messenger and Windows Live Messenger clients had to update or lose access to the service.

Storms recommended that corporate IT admit that unauthorized instant messaging software is being used on their networks. "Enterprise IT teams that have been ignoring IM clients because they are not part of the 'official' infrastructure would be well advised to take steps to bring an IM client onto their supported platform and make sure their antivirus and spyware vendors work with their selected client," he said in an e-mail.

Yahoo, which patched Messenger twice last month, did not immediately respond to a request for confirmation of the newest flaw and queries about a patch timeline.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?