MSN Messenger flaw highlights 'serious' security threat

The recent flaw plugged by Microsoft in its MSN Messenger software highlights a serious security threat to enterprise security, according to analysts.

Last Friday, Microsoft forced its millions of MSN Messenger users to download a new version of the software to plug a security vulnerability. The mandatory upgrade began after a security company posted information that would help a would-be attacker exploit the vulnerability. MSN Messenger users were then greeted with a notice to upgrade before they could open their instant messaging clients.

Analyst firm Gartner commended Microsoft for acting so quickly to control the problem by locking out vulnerable clients but it warned that future threats may not be so easily dealt with and enterprises may have to take the matter into their own hands.

"Next time an IM exploit emerges, Microsoft or another IM provider may not be able to respond as quickly or as effectively. Enterprises must take responsibility for ensuring that the use of IM does not compromise their security. If necessary, they must be able to temporarily shut it down when a serious security threat emerges," said Gartner analyst Lawrence Orans in an advisory.

Foad Fadaghi, senior industry analyst at Frost & Sullivan Australia, said that although some companies have set up security policies for IM, many have got so comfortable using the free consumer version they could find themselves in trouble if they are forced to shut the service down because of security issues.

"A lot of companies have left themselves quite exposed by using public IM software but as you see more threats happening to IM, more companies are setting up policies and secured systems. However, IM is a primary communications method and if they start talking about turning it off they will damage their business," said Fadaghi.

Fadaghi said one good thing to come from the MSN Messenger vulnerability is that the security threat from IM has been highlighted.

"It wasn't on the list of things that the CIO was worried about. If anything, the CIOs out there may now start seeing IM as a serious threat to corporate security," said Fadaghi.

Gartner's Orans said that IM's popularity is making it unrealistic for a company to block the service completely, which leaves administrators with a number of options.

"In many enterprises, one or more business units can make a compelling case for the need to use IM. Enterprises have three options: Implement an enterprise IM solution, deploy a solution that makes it possible to build policies around public IM services, or do both," said Orans.

Advertisement

Talkback 2 comments

    For a little balance...it migh ...Anonymous -- 18/02/05

    For a little balance...it might be worth looking at the impact of the flaw. Ok, how long were your family and kids vulnerable to IM web-stalkers with the technical ability to exploit it? The industry has a responsibility to admit this to the public in a way they can understand, not just to discuss this amongst ourselves using technical jargon.

    We may be proficient enough to secure our systems, while the general public and tomorrow's market place are left in the dark. They are entitled to make informed choices - and I predict there will be a Senate enquiry into the "security industry" within the next 18 months. You know why.

    i've been having a lot of prob ...Anonymous -- 21/02/05

    i've been having a lot of problems with msn free hotmail service it scans my email & removes pictures. it rescans email that was sent to me& all ready scanned & removes attachments. it tells me that it found a virus in it one time then the next time not.i've run virus scans & they show nothing was found thru mcAfee & windows
    i called msn support they told me theres nothing
    they can do because its a free version. any help you can give me will be very much appreciated thank you,in advance, jc

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured