CVE-2009-0647Improper Input Validation in Microsoft Windows Live Messenger

Severity
5.0MEDIUMNVD
EPSS
18.6%
top 4.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 2

Description

msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. NOTE: this has been reported as a format string vulnerability by some sources, but the provenance of that information is unknown.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-vgwx-7mjc-5w5g: msnmsgr2022-05-02
CVEList
CVE-2009-0647: msnmsgr2009-02-19
CVE-2009-0647 — Improper Input Validation in Microsoft | cvebase