Feeds

MS warns of forced Messenger update

More fallout from ATL snafu

Beginner's guide to SSL certificates

Microsoft has outlined plans to push a mandatory Windows Live Messenger upgrade in order to plug a security hole related to a vulnerable code library.

The security vulnerability stems from the use of a vulnerable version of Microsoft's Active Template Library (ATL). A programming error involving the inclusion of an extra "&" character meant that any software packages that made use of the ATL library template inherited a critical software flaw.

Software developers across the IT industry used the vulnerable ATL library to write application components, or more specifically Component Object Model code, including ActiveX controls.

In late July, Microsoft issued a pair of out of sequence patches to fix the ATL bug in Internet Explorer and Visual Studio, its development platform. As part of the August patch Tuesday update, Microsoft patched five more software packages to defend against bugs stemming from the ATL snafu.

Windows Live Messenger 8.1 and 8.5 are both also vulnerable as a result of the same ATL problem. Microsoft has already begun offering a voluntary update but, starting later this month, will force users to upgrade to the the latest version of Live Messenger if they want to use Microsoft's IM service.

Users already on version 14 of Live Messenger will also be pushed towards the latest variant, version 14.0.8089, but mandatory updates in these cases won't happen until late October, as explained in a blog post by Microsoft here.

Microsoft's post on its Windows Live blog goes on to explain the featured improvements in the new version of Windows Live Messenger, including improved photo sharing and personalisation features. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
Ello? ello? ello?: Facebook challenger in DDoS KNOCKOUT
Gets back up again after half an hour though
Desperate VXers enslave FREEZERS in DDoS bot
Updated Spike malware targets Asia
Heatmiser digital thermostat users: For pity's sake, DON'T SWITCH ON the WI-FI
A stranger turns up YOUR heat with default password 1234
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.