AOL Instant Messenger Local File Execution Vulnerability
BID:6027
Info
AOL Instant Messenger Local File Execution Vulnerability
| Bugtraq ID: | 6027 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2002 12:00AM |
| Updated: | Oct 22 2002 12:00AM |
| Credit: | Discovery is credited to "Blud Clot" <[email protected]>. |
| Vulnerable: |
AOL Instant Messenger 4.8.2790 |
| Not Vulnerable: |
AOL Instant Messenger 5.0.2938 AOL Instant Messenger 4.8.2616 AOL Instant Messenger 4.8 .2646 AOL Instant Messenger 4.7.2480 |
Discussion
AOL Instant Messenger Local File Execution Vulnerability
AOL Instant Messenger (AIM) is prone to an issue which may allow attackers to execute arbitrary files on the client system. It is possible to send a malicious link which references local files to a user of the client. When the link is visited, the referenced file on the client's local filesystem will be executed.
To exploit this issue, the attacker must know the exact location of the file to be executed. Additionally, there can be no spaces in the path or filename. This limits exploitability, since files must be on the same partition and command line arguments cannot be supplied.
Versions other than AOL Instant Messenger 4.8.2790 do not seem to be affected by this vulnerability. The vulnerability was reported for Microsoft Windows versions of the client.
AOL Instant Messenger (AIM) is prone to an issue which may allow attackers to execute arbitrary files on the client system. It is possible to send a malicious link which references local files to a user of the client. When the link is visited, the referenced file on the client's local filesystem will be executed.
To exploit this issue, the attacker must know the exact location of the file to be executed. Additionally, there can be no spaces in the path or filename. This limits exploitability, since files must be on the same partition and command line arguments cannot be supplied.
Versions other than AOL Instant Messenger 4.8.2790 do not seem to be affected by this vulnerability. The vulnerability was reported for Microsoft Windows versions of the client.
Exploit / POC
AOL Instant Messenger Local File Execution Vulnerability
The following example was provided:
<a href ="../../../../progra~1/trojan/trojan.exe">www.example.com</a>
The following example was provided:
<a href ="../../../../progra~1/trojan/trojan.exe">www.example.com</a>
Solution / Fix
AOL Instant Messenger Local File Execution Vulnerability
Solution:
This issue is reportedly only present in AOL Instant Messenger 4.8.2790. Users may address this vulnerability by upgrading or downgrading to another version.
Solution:
This issue is reportedly only present in AOL Instant Messenger 4.8.2790. Users may address this vulnerability by upgrading or downgrading to another version.
References
AOL Instant Messenger Local File Execution Vulnerability
References:
References: