VoIPshield Uncovers Security Flaws in Microsoft VoIP ProductsMedia stream vulnerabilities affect millions of corporate desktops worldwideNovember 12, 2008VoIPshield Laboratories, the research division of VoIPshield Systems Inc., is making its first-ever announcement in a new category of research related to security vulnerabilities in VoIP and Unified Communications (UC) systems. These vulnerabilities affect applications that use media stream protocols like RTP (Real-time Transport Protocol), a popular standardized packet format for delivering audio and instant messaging over the Internet. The Microsoft products affected are Office Communications Server 2007, Office Communicator and Windows Live Messenger. These products deliver software-powered VoIP, presence, instant messaging and audio/video/Web conferencing functionality to end users. Microsoft estimates that over 250 million computers worldwide run these applications. All use RTP to deliver the content of the message; therefore all are vulnerable to this class of attack.
“Most of the attention in enterprise VoIP/UC security has been paid to the control channel, where SIP and other signalling protocols are used,” said Ken Kousky, CEO of
|