An unpatched Yahoo Messenger vulnerability allows attackers to change people’s status messages and possibly perform other unauthorized actions. The vulnerability was discovered in the wild by security researchers from antivirus vendor BitDefender. The flaw appears to be located in the application’s file transfer API (application programming interface) The vulnerability can be leveraged by attackers to earn money through affiliate marketing schemes or to spam malicious links that point to drive-by download pages. Yahoo was notified about the vulnerability through the appropriate channels, but did not immediately respond to a request for comment.”]

