CERT Warns of Yahoo! Messenger Vulnerabilities

It may be a good time to firm up your organization's policies on use of the Yahoo! instant messaging client.

The CERT/CC issued an alert Wednesday about multiple vulnerabilities in the Yahoo! Messenger client for Windows. Among other problems, one flaw could allow malicious users to execute arbitrary code with the privileges of the victim user.

Yahoo! patched a number of problems in February with version 5,0,0,1058, and a few more recent problems with versions 5,0,0,1065 and 5,0,0,1066 in late May. However, the CERT/CC warns that a problem with Yahoo!'s distribution server ended with some users receiving version 5,0,0,1034, which has none of the patches, after May 22.

Although the CERT/CC said that the Yahoo! distribution server problem had been fixed, an attempt by ENT to move to the latest version on Wednesday failed. The Yahoo! server offered an alternative download location that installed another pre-February patch version -- 5,0,0,1045.

A subsequent attempt resulted in a successful install of 5,0,0,1066, but serves as a warning for administrators to make sure that users verify that they have installed the correct version.

Yahoo! is one of several popular instant messaging clients offered as free Internet downloads. In a recent report, an analyst at Gartner warned IT managers to carefully monitor use of instant messaging clients in the enterprise as the software could become a springboard for future multi-pronged attacks along the lines of Code Red and Nimda. A vulnerability in Microsoft's MSN Messenger prompted the Gartner warning.

The CERT/CC bulletin is available here:

Yahoo! Messenger update can be obtained here:

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.


  • Performing a Storage Refresh on Windows Server 2016, Part 2

    Earlier, Brien walked through the steps of preparing a physical Windows Server 2016 machine for a storage refresh. Now, he shows how to complete the process, all the way to OS restoration.

  • New Office App Coming to Windows 10 Users

    Microsoft is delivering a new Office app for Windows 10 consumer and business users over the new few weeks, according to a Wednesday announcement.

  • Microsoft Warns .NET Core 1.0 and 1.1 Losing Support in June

    Microsoft gave notice this week that .NET Core 1.0 and 1.1 will fall out of support on June 27, 2019.

  • Microsoft Publishes Windows Deadlines on Upgrading to SHA-2

    Microsoft on Friday described its 2019 timeline for when it will start distrusting Secure Hash Algorithm-1 (SHA-1) in supported Windows systems, as well as in the Windows Server Update Services 3.0 Service Pack 2 management product.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.