AIM Pro
A newly discovered flaw affects AIM 6.1, 6.2 beta, AIM Pro and AIM Lite

IM flaw hits millions of AOL users

Users exposed to immediate high-risk attacks, warns security firm

Written by Ian Williams

Enterprise security firm Core Security Technologies has disclosed a vulnerability that could affect millions of AOL Instant Messenger users.

Attackers exploiting the vulnerability could remotely execute code on a user's machine, and exploit Internet Explorer bugs without user interaction.

Core Security has informed AOL of the problem, but warned that details of the flaw have already appeared on several bug-tracking sites.

"This vulnerability poses a significant security risk to millions of AIM users," said Iván Arce, chief technology officer at Core Security.

"We have alerted AOL to this threat and provided full technical details, but the vulnerability has emerged on several public bug-tracking websites.

"Therefore, we believe it is necessary to bring precise details about this issue to light immediately, so that AIM users and organisations can be made aware of the threat, assess their risk and take appropriate measures."

The flaw in AIM 6.1, 6.2 beta, AIM Pro and AIM Lite exposes workstations running these IM clients and their users to several immediate high-risk attacks.

All of the vulnerable AIM clients include support for enhanced message types that enable AIM users to use HTML to customise text messages with specific font formats or colours.

The vulnerable AIM clients use an embedded Internet Explorer server control to render this HTML content.

However, as this input is not checked before it is rendered, an attacker could deliver malicious HTML code as part of an instant message to directly exploit Internet Explorer bugs without user interaction.

AOL has acknowledged the problem and has urged users to upgrade to the latest version of the AIM beta client or use its web-based AIM Express service until the problem has been addressed.

Tags:

Further reading

Google plugs Gmail security hole

Filter-injection attack allowed forwarding of emails to third parties   More...

Excel 2007 fails maths test

Spreadsheet software displays incorrect numbers   More...

Virgin Digital shuts up shop

Download service to be closed next month   More...

Zero-day flaw hits Windows XP

Vulnerabilities in MFC42 and MFC71 could allow remote code execution   More...

Related articles

Mega Apple patch fixes iPhone, Safari, OS X bugs

Update repairs 54 vulnerabilities   More...

VMware issues 'critical' security alert

Major problem with shared folders   More...

Microsoft patches eight 'critical' holes

August update covers four web browsing risks   More...

'Italian job' attacks spread worldwide

10,000 websites now hosting malicious attack code   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement