Web Browsers

  1. Home
  2. Computing & Technology
  3. Web Browsers
photo of Scott Orgera

Scott's Web Browsers Blog

By Scott Orgera, About.com Guide to Web Browsers

AOL Fixes Critical Instant Messenger Vulnerability

Monday October 15, 2007

A security flaw in AOL Instant Messenger, also known as AIM, has been fixed. Sort of. Reported last month by Core Security Technologies and expert Aviv Raff, the vulnerability utilized the popular instant messaging program and the Internet Explorer web browser to take control of a PC.

AOL released a new version of AIM 6.5 (6.5.4.16) this week which corrects the flaw. While Raff states that this latest release does indeed fix the specific attack vector of the vulnerability, it does not utilize the Local Zone lockdown. What this means is a skillful attacker could still potentially find a way to inject a malicious script into an instant message window. Therefore he has postponed the release of his proof-of-concept, lest it fall into the wrong hands.

Nevertheless, Windows users running AIM are encouraged to upgrade their software immediately.

(Photo © AOL LLC)

Comments

No comments yet. Leave a Comment

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Discuss

Community Forum

Explore Web Browsers

More from About.com

Web Browsers

  1. Home
  2. Computing & Technology
  3. Web Browsers

©2008 About.com, a part of The New York Times Company.

All rights reserved.