This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.
This signature detects attempts to exploit a buffer overflow with a Yahoo ActiveX control which could result in remote code execution.
Yahoo! Messenger Webcam Upload ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
This issue occurs when an excessive amount of data is passed to the application. The ActiveX control uses CLSID: DCE2F8B1-A520-11D4-8FD0-00D0B7730277.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of applications that use the affected control (typically Internet Explorer).
- Yahoo! Messenger 8.0 2005.1.1.4, 8.0, 8.0.1, 8.1
- Yahoo! Webcam ActiveX Control 188.8.131.52
Ensure that all vendor supplied patches and security updates have been applied.