CVE-2005-2225

Microsoft MSN Messenger - Denial of Service via Plaintext Message with .pif String

Title source: llm
STIX 2.1

Description

Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has been reported that Gaim is also affected, so this may be an issue in the protocol or MSN servers.

References (3)

Core 3
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014444
Exploit, Vendor Advisory x_refsource_misc
http://www.digitalparadox.org/viewadvisories.ah?view=45
Exploit, Vendor Advisory, URL Repurposed x_refsource_misc
http://www.messenger-blog.com/?p=146

Scores

EPSS 0.1644
EPSS Percentile 96.7%

Details

Status published
Products (1)
microsoft/msn_messenger_service
Published Jul 12, 2005
Tracked Since Feb 18, 2026