Executive brief
AOL Instant Messenger is a communication tool used for real-time messaging. A vulnerability in the application allows a remote attacker to crash a user's software or entire system by sending a specially crafted hyperlink. This results in a denial of service, disrupting communication and potentially causing data loss from unsaved work during the system crash.
Technical details
A denial of service vulnerability exists in early versions of AOL Instant Messenger (AIM). The flaw is triggered when the client processes a specifically malformed or malicious hyperlink sent by a remote user over the network. Successful exploitation can lead to an application hang or a complete system crash (BSOD/kernel panic equivalent). No authentication is required to send the message to a target user, making this a low-complexity remote attack. While the exact root cause in the URI parsing logic is not detailed in the legacy record, the impact is limited to availability.
Affected products
- AOL Instant Messenger
Timeline
- 1998-02-01: disclosed