MSN Messenger users are being forced to upgrade to Windows Live Messenger in response to a vulnerability in the older program.
According to a blog post by a Microsoft security program manager who identified himself only as 'Anand', the instant messaging service requires users to update to the safe Live Messenger 8.1.
"When a user using an older version of Messenger tries to log in, the client will help the user with a mandatory upgrade to Messenger 8.1," Anand said.
The update, he added, will be rolled out over several days, so users running MSN Messenger 6.2, 7.0 and 7.5, as well as Live Messenger 8.0, may not see the notification immediately. The dialogue reads: "A newer version is available. You must install the newer version in order to continue. Would you like to do this now?"
Windows Live Messenger 8.1 has been offered to users since February, but until now, the update has been optional. "Some of you might feel this inconvenient, but in order to protect you and protect the health of the network, we have chosen to take this step," Anand added.
The move isn't unprecedented. In early 2005, Microsoft made patched versions of MSN Messenger mandatory when security researchers posted attack code that targeted flaws that had been disclosed only hours before.
The vulnerability that prompted the compulsory upgrade was described by Microsoft in Tuesday's MS07-054 security bulletin, which only recommended that users upgrade. A bug in Messenger's webcam and video chat features was reported late last month on a Chinese-language security mailing list, and exploit code quickly followed. Users who accepted malicious webcam or video chat invitations risked losing control of their PC to hijacking attackers.
The enterprise-grade version of Microsoft's instant messaging client - Office Communicator - does not contain the buggy component, and is not vulnerable. But businesses whose users run MSN Messenger or Live Messenger 8.0 that rely on Windows Server Update Services to patch PCs, have a hoop or two to jump through, according to messages on the WSUS support newsgroup.
"Why isn't MS07-054 showing up in WSUS?" asked a user tagged as Henry Johnston. "The security bulletin says the update is being distributed via MSN Messenger itself, but that's no use - it still leaves us having to log into every computer individually, one by one, in order to install it."
Others who responded to Johnston said that the MSN Messenger and Live Messenger updates weren't deployable via WSUS. "Since the product [MSN/Windows Live Messenger] is considered an [out-of-band] product, it doesn't really fit in with the normal enterprise deployment methods that we have," wrote an unidentified Microsoft support representative.
Consumers weren't happy with the situation, either. The mandatory upgrade to Live Messenger got a thumbs down from many users posting to Microsoft's IM support newsgroups. "Well, I tried it and HATE it and can't revert it," complained a user with the nickname bodeelifts on the microsoft.public.msn.messenger forum. "I am absolutely livid. It is hard on the eyes, not easy to use, is filled with too many bells and whistles that I have no need for, and I am sick and tired of being forced into things I don't want."
Some users of the now-obsolete MSN Messenger said they were ditching Microsoft's IM client, and had switched to alternatives, such as Cerulean Studio's free Trillian or the open-source Pidgen, formerly known as Gaim.
However, one edition of MSN Messenger will continue to work, Microsoft said. "Because Windows 2000 isn't supported by Windows Live Messenger 8.1, we will provide an updated version of MSN Messenger 7.0," said Anand on the Messenger blog. "We will upgrade Windows 2000 users to the updated version of MSN Messenger 7.0 after the Windows Live Messenger upgrades."
The revamped MSN Messenger will carry version number 7.0.0820.





Comments
natalie said: argh i have only just found out about this lot i thought i had lost my msn forever ive got windows 2000 i havent chatted to my friends for weeks nowwhen will i be able to get msn back please my son has been trying to get me to use other things but i dont like them
Shane said: This is what gets me When I upgrade because I cant log on to msn without upgrading It only lasts until I restart my computer then the same message will appear when I try to log in as if I never got the new version This happens every time I shut down my computer or restart and it is really starting to bug me At first I thought it was some kind of virus and now Im being told that it is MSN doing this They are trying to prevent bogs and they have created another big bug when I never had a problem with the old versions
Cliff S said: I found this on Wikipedia but I dont know exactly how long this will last If you want to continue to use 75 simply set Compatibility mode for it to Windows 2000 and it should work I did this and it works running 750322
lora said: y r u forcin us to upgrade i cant even go into msn n d little information box is not showin long enough for me to click upgrade or not which is pissin me off i just wants to chat to my friends on msn n i avnt been able to do tht al day 2day do not want an upgrade just give me bak my old one i like it tht way
Bob said: As a Win2000 user I was forced to update from messenger 62 to the new version 7 today Urgh I am now reminded why i binned version 7 when it came out 2 years ago and went back to 62 Version 7 is cluttered a memory hog and is harder to use Why could they have not released an update to version 62 Th last good version in my opinion
David Forrest said: I downgraded to 75 because the new one would never connectLuckily it appears that Microsoft have actually sorted that out because it connects properly now
GALLEY SLAVE said: Had to download it but I will reserve judgement til laterBut from ones inbox page it needs a direct link to MY MSN in fact an all round link system is needed to all ones personalfavorite pages after all one has already signed in
mike said: Its free software If you dont like it stop bleating and use something else
messblue team said: I think microsoft as just shot them selfs in the foot big time i dont belive for one minute about all older versions having thisexpliot in the webcam and video chat featuresif this was the case why didnt they just make a patch for itanyone who needs a open sorce messenger can download one from here wwwmessbluetk
chariti said: I am very uncomfortable with being forced to take anything even if its for my own good I am usually flexible with most things Microsoft does with a sigh and a shrug I do it as recommended But this is too much a forced action I am switching after about a decade of MSN IM
gerdina said: yes microsoft made me to update to 81 i was on msn75 i have been trying to re install the 75 as i like this one but no luck dont like the 81 gerdina