AIM Pro
A newly discovered flaw affects AIM 6.1, 6.2 beta, AIM Pro and AIM Lite

IM flaw hits millions of AOL users

Users exposed to immediate high-risk attacks, warns security firm

Ian Williams

Enterprise security firm Core Security Technologies has disclosed a vulnerability that could affect millions of AOL Instant Messenger users.

Attackers exploiting the vulnerability could remotely execute code on a user's machine, and exploit Internet Explorer bugs without user interaction.

Advertisement

Core Security has informed AOL of the problem, but warned that details of the flaw have already appeared on several bug-tracking sites.

"This vulnerability poses a significant security risk to millions of AIM users," said Iván Arce, chief technology officer at Core Security.

"We have alerted AOL to this threat and provided full technical details, but the vulnerability has emerged on several public bug-tracking websites.

"Therefore, we believe it is necessary to bring precise details about this issue to light immediately, so that AIM users and organisations can be made aware of the threat, assess their risk and take appropriate measures."

The flaw in AIM 6.1, 6.2 beta, AIM Pro and AIM Lite exposes workstations running these IM clients and their users to several immediate high-risk attacks.

All of the vulnerable AIM clients include support for enhanced message types that enable AIM users to use HTML to customise text messages with specific font formats or colours.

The vulnerable AIM clients use an embedded Internet Explorer server control to render this HTML content.

However, as this input is not checked before it is rendered, an attacker could deliver malicious HTML code as part of an instant message to directly exploit Internet Explorer bugs without user interaction.

AOL has acknowledged the problem and has urged users to upgrade to the latest version of the AIM beta client or use its web-based AIM Express service until the problem has been addressed.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Gmail

Google plugs Gmail security hole

Filter-injection attack allowed forwarding of emails to third parties

Microsoft Excel

Excel 2007 fails maths test

Spreadsheet software displays incorrect numbers

Virgin Digital shuts up shop

Download service to be closed next month

Zero-day flaw hits Windows XP

Vulnerabilities in MFC42 and MFC71 could allow remote code execution

Related whitepapers

Related jobs

Most watched

Summit video: Intel discusses processors designed for data overload (part one of two)

Intel explains how its Xeon processors can handle data-intensive apps

Summit: Intel discusses processors for data overload (part 2 of 2)

More thoughts on how servers can help manage overload

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

deloitte

Summit interview: Deloitte discusses security implications of the data deluge

We chat to Mike Maddison, UK head of Security, Privacy...

ibm logo

IBM boosts mobile shopping with WebSphere Commerce

Update designed to give mobile users a richer, more personalised...

Summit: Intel discusses processors for data overload (part 2 of 2)

More thoughts on how servers can help manage overload

chrome logo

Google plans a Mac version of Chrome

A Mac-friendly version of the browser is in the pipeline

Primary Navigation