All the latest UK technology news, reviews and analysis

IM flaw hits millions of AOL users

by Ian Williams

02 Oct 2007

Be the first to comment

  • Tweet this
AIM Pro
A newly discovered flaw affects AIM 6.1, 6.2 beta, AIM Pro and AIM Lite

Enterprise security firm Core Security Technologies has disclosed a vulnerability that could affect millions of AOL Instant Messenger users.

Attackers exploiting the vulnerability could remotely execute code on a user's machine, and exploit Internet Explorer bugs without user interaction.

Core Security has informed AOL of the problem, but warned that details of the flaw have already appeared on several bug-tracking sites.

"This vulnerability poses a significant security risk to millions of AIM users," said Iván Arce, chief technology officer at Core Security.

"We have alerted AOL to this threat and provided full technical details, but the vulnerability has emerged on several public bug-tracking websites.

"Therefore, we believe it is necessary to bring precise details about this issue to light immediately, so that AIM users and organisations can be made aware of the threat, assess their risk and take appropriate measures."

The flaw in AIM 6.1, 6.2 beta, AIM Pro and AIM Lite exposes workstations running these IM clients and their users to several immediate high-risk attacks.

All of the vulnerable AIM clients include support for enhanced message types that enable AIM users to use HTML to customise text messages with specific font formats or colours.

The vulnerable AIM clients use an embedded Internet Explorer server control to render this HTML content.

However, as this input is not checked before it is rendered, an attacker could deliver malicious HTML code as part of an instant message to directly exploit Internet Explorer bugs without user interaction.

AOL has acknowledged the problem and has urged users to upgrade to the latest version of the AIM beta client or use its web-based AIM Express service until the problem has been addressed.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Data Delivery Support Analyst

We have been given the privilege of recruiting for a...

Quant Trader - Equities - Leading Prop shop

My client is a proprietary, electronic trading firm and...

Senior Project Manager (Telecoms - 9 month FTC)

Our client is looking for a Senior Project Manager (Telecoms...

Business Analyst - Surrey

Business Analysts are being sought by my leading financial...

To send to more than one email address, simply separate each address with a comma.