CVE-2002-0472

MSN Messenger Service 3.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.

References (4)

Core 4
Core References
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/262906
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8582.php
Various Sources x_refsource_misc
http://www.encode-sec.com/esp0202.pdf
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4316

Scores

EPSS 0.1188
EPSS Percentile 95.7%

Details

Status published
Products (1)
microsoft/msn_messenger 3.6
Published Aug 12, 2002
Tracked Since Feb 18, 2026