Intruders Could Take AIM at AOL

A security firm has notified AOL that a potentially critical security hole exists in its instant messaging software, commonly referred to as AIM, that would permit an intruder to gain complete control over a user's system.

Officials from Core Security Technologies said it contacted AOL about the flaw late last month. While company executives at AOL say the hole has been closed, Core Security officials counter that the fix doesn't go far enough. However, one Core Security official said it remains unclear whether anyone has successfully exploited the hole.

The flaw resides in the most recent beta releases of AIM 6.1 and 6.2. Core Security has also found the hole in the AIM Pro, intended mainly for business users, and in AIM Lite. The company said the problem doesn't exist in version 5.9 of AIM nor in AIM 6.5, a product also currently in beta testing.

The security hole arose, according to Core Security, because of the way the affected versions allow instant messaging users to augment their conversations with a number of fonts and pictographic "emoticons." The flawed versions of AIM do this by using Microsoft Corp.'s Internet Explorer program to render images, they explained.

Core Security contends that the real problem involves AIM enabling full access to all of Internet Explorer's functions, including the ability to carry out programming commands and direct them at Web sites. By embedding specific commands in an IM session, hackers can direct a user's system to do things such as visit malicious Web sites where even more bad code could be installed.

AOL officials responded by saying the issue has been resolved and that users should feel "completely safe."

Posted by Ed Scannell on September 27, 2007


Featured

  • Microsoft Appoints Althoff as New CEO for Commercial Business

    Microsoft CEO and chairman Satya Nadella on Wednesday announced the promotion of Judson Althoff to CEO of the company's commercial business, presenting the move as a response to the dramatic industrywide shifts caused by AI.

  • Broadcom Revamps VMware Partner Program Again

    Broadcom recently announced a significant update regarding its VMware Cloud Service Provider (VCSP) program, coinciding with the release of VMware Cloud Foundation (VCF) 9.0, a key component in Broadcom’s private cloud strategy.

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.