MSN flaw highlights dangers of instant messaging
MSN flaw highlights dangers of instant messaging

IM security threat still being ignored

Recent MSN incident should be seen as a wake up call, warns Gartner

Robert Jaques

A recently discovered security flaw in MSN Messenger demonstrates that instant messaging (IM) presents a serious security threat and should act as a wake up call for enterprises, industry experts have warned.

According to Gartner, firms must "implement comprehensive IM policies now" after the MSN Messenger vulnerability prompted Microsoft to restrict access to its service in a bid to prevent the exploit from spreading.

Advertisement

Gartner senior analyst Lawrence Orans said: "The MSN Messenger exploit highlights the risks of not establishing and implementing an enterprise IM policy."

"The MSN Messenger client, like those for Yahoo Messenger, AOL Instant Messenger and other IM services, is available for download free of charge.

"As a result, IM is so widely used that most enterprises have no idea how many IM clients are installed on their systems or how much IM traffic passes through their networks."

The warning comes after Microsoft moved to lock out any users not running the latest versions of its MSN Messenger and Windows Messenger clients after proof of concept of a vulnerability was posted on the internet.

The problem centred on the inability of older versions of MSN Messenger and Windows Messenger to properly handle corrupted image files. By exploiting this vulnerability, an attacker could take control of an affected system.

"Microsoft acted quickly to control this malicious code outbreak by denying access to clients that were not up to date," said Orans.

"However, the next time an IM exploit emerges, Microsoft or another IM provider may not be able to respond as quickly or as effectively.

"Enterprises must take responsibility for ensuring that the use of IM does not compromise their security. If necessary, they must be able to temporarily shut it down when a serious security threat emerges."

Gartner advised that, because IM has become so popular, it is rapidly becoming unrealistic to block IM traffic entirely. In many enterprises, one or more business units can make a compelling case for the need to use the technology.

The analyst firm believes that enterprises have three options: implement an enterprise IM system; deploy a product that makes it possible to build policies around public IM services; or do both.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

Salesforce.com on the new Chatter service

Company explains the need for collaboration service

t-mobile logo

V3.co.uk weekly debrief, 20 Nov 09

This week we round up the major vendor conference events, plus T-Mobile sells customer data

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

t-mobile logo

V3.co.uk weekly debrief, 20 Nov 09

This week we round up the major vendor conference events,...

Apple iPhone apps

Top 10 articles, 20 Nov 2009

An App Store upset for Apple, and a scandal at...

Biz Stone

Twitter founder details commercial account plans

Biz Stone says paid-for accounts will give users access to...

Cloud computing

Enisa launches comprehensive cloud security report

EU security agency provides checklist for firms looking to vet...

Primary Navigation