Risk: High
Two highly critical Yahoo! Messenger flaws have been patched after proof-of-concept code was released.
The flaws are both caused by a buffer overflow error in the Yahoo! Webcam Upload (ywcupl.dll) ActiveX control and successful exploitation can permit arbitrary code execution. The vulnerabilities are confirmed in version 8.1.0.249 and other versions may also be affected.
Yahoo! recommends updating to the latest version at: