Core Security CTO Finds Major Vulnerability in AIM, IE7

By Scott M. Fulton, III | Published September 25, 2007, 5:07 PM

The Associated Press reported this afternoon that the chief technology officer of the company that makes Core Impact, a very well-known penetration testing product for enterprise networks, has gone public with the discovery of a new and significant vulnerability affecting AOL Instant Messenger, on systems where Internet Explorer 7 is also installed.

Core Security CTO Iván Arce told the AP that the current AIM 6.1, including the Pro and Lite versions, as well as the beta of AIM 6.2 all utilize Internet Explorer 7 for some of their rendering functions, including graphic emoticons. The interaction between AIM and IE7 apparently takes place over a link that Arce says he's proven can be exploitable, in demonstrations last month to officials of AOL's parent company, Time Warner.

Certain commands issued during an IM session can apparently enable full remote access to IE7, according to the AP report's assessment of Arce's claim. Users of the Web-based alternative to AIM would not experience this problem, he said.

For more: Core CTO: Highly Exploitable AIM Bug Could Lead to System Hijack

Comments

View comments by with a score of at least

Their are still people using AIM? wow....what am I gonna find out next, hampsterdance.com is the most popular site on the web???

Score: 0

|

*laughs*

Excellent. I had totally forgotten about that.

Time to walk through the building and set it as the homepage of the folks who've left their PCs without locking the session.

If that doesn't teach 'em...

Score: 0

|

Is AIM 4.8 affected?

Score: 0

|

" Iván Arce told the AP that the current AIM 6.1, including the Pro and Lite versions, as well as the beta of AIM 6.2 all utilize Internet Explorer 7 for some of their rendering functions, including graphic emoticons."

Didn't see AIM 4.8 mentioned in there, but since AIM 4.8 may no longer be supported by aol (I don't know if it is or not), it will not be mentioned anyway.

Kinda like the fact that the 2005 WMF exploit actually affected Windows 95 and Windows 3.1 as well, but since Microsoft retired support for those ages ago, they needn't mention them.

Score: 0

|

4.8 probably came out before IE7 so most likely not. I don't use AIM so I'm not completely sure.

Score: 0

|

How many does this make for IE over the past four months? Wasn't new versions of Vista/IE supposed to make us safer?

Aww, I hear toolie crying.

Score: 0

|

Gee, don't all software products have the possibility of holes? Last I checked people still made mistakes and pencils still had erasers. Oh wait, you just wanted another chance to attack IE and another user. You know, from someone who tries to act so professional on other sites (DontationCoder, the great software list), you sure don't know how to do so on a simple review site.

Score: 0

|

Maybe I am reading it wrong, but the problem is with AIM and how it uses 7 for rendering that is the problem. Too quick to jump on IE7. Maybe wait until the full details are brought to light before you condem the product.

Score: 0

|

Posting 101: You fail.

Nice double-post. I imagine the excitement at the thought of being able to make yet another MS-Troll post was just too much for you.

Next time, try reading the article first.

Score: 0

|

How many does this make for IE over the past four months? Wasn't new versions of Vista/IE supposed to make us safer?

Aww, I hear toolie crying.

Score: 0

|

Maybe I am reading it wrong, but the problem is with AIM and how it uses 7 for rendering that is the problem. Too quick to jump on IE7. Maybe wait until the full details are brought to light before you condem the product.

Score: 0

|

ROFLMAO....

Reading Comprehension 101: You fail.

Also note than under protected mode, even "full access to IE7" is pretty damned useless.

Score: 0

|

We ban AIM at work and I ban it at home. It's useless. IE7 is part of Vista so you live with it, even if you load FF or Opera or whatever.

Score: 0

|

and why not. with microsoft being as secure as it is, what could go wrong

Score: 0

|

I don't use IE OR AIM, so nothing to worry about.

Score: 0

|

Read more carefully. It doesn't matter if YOU use IE7... AIM itself uses IE7.

You don't use AIM at all so you're not affected, just thought I'd make that distinction.

I use Trillian Astra myself.

Score: 0

|

Trillian is the sheeyat

Score: 0

|

Pretty much assume AIM and Yahoo Messenger have security issues, public disclosed or not.

Score: 0

|

I gather that this exploit can only occurr with both AIM and IE7 working together. This much I figured out on my own. My question is: where is the actual vulnerability, IE7 or AIM (or both)?

Score: 0

|

"Certain commands issued during an IM session.."

To me, this is an AIM problem with it's poor integration with IE7. The developers of IE7(Microsoft) should not be held responsible for the actions of others. Developers, on a whole, cannot be faulted by the intentional/unintentional use of their product - though measures should be taken to keep if from happening in the future now that it has been brought to light.

Though the actual vulnerability is not described in detail, it is often puzzling how others jump to conclusions and bash a product, in this case IE7, without all the facts. I too, wish to know more and look forward to the follow-up article. If BetaNews has their initial information correct, this seems to be an AIM issue that is affecting IE7.

Score: 0

|

BAM!

Another day, another windows vulnerability... "laughs"

Score: 0

|

How many patches did Apple release again in the past few months?

/thank you
//No piece of complex software is 100% including YOURS.

Score: 0

|

Perhaps you need to read that again... I don't see anything about a "windows" vulnerability. I see an IE vulnerability.

EVERY software has vulnerabilities, however. NO web browser or OS is immune.

Score: 0

|

Exactly! And how many holes have been found in the over-hyped iProne?

Score: 0

|

Interesting that an Apple fan-boy would comment on browser vulnerabilities with all of the vulnerabilities found recently in Safari!

Score: 0

|

on windows? safari has only had 4 patches since it's 2.0 launch. 3 on windows isn't even out of beta.

Score: 0

|

What? 2 patches? fomg the world will collapse.

Score: 0

|

BAM!

Another MS troll hits the web and totally fails at reading comprehension.

You guys are such good entertainment, who needs TV?

Score: 0

|

It's an AIM vulnerability. Microsoft is in no way responsible, from what it sounds like. Even if it utilizes some sort of IE exploit or vulnerability, the only excuse for using IE7 for what AOL is doing with it is lazy programming on the part of AOL.

Score: 0

|

... and 3 on windows has already had two patches, if I'm not mistaken.

And neither of them fixed the problem I've been having where the menu bar is invisible. I'm not on a Mac here!

Annnd I just went to run it again and it crashed on startup. Boo. But then again a few things are broken on here ATM so I can't really blame Apple for that.

Score: 0

|

Agreed!

Score: 0

|

you're running a beta app on a platform it's not native to. i'm shocked your computer hasn't imploded

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?