VulnerabilityModified
CVE-2002-1591
AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass intended access restrictions.
HIGH 7.5EPSS 1.68%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass intended access restrictions.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.68% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- aol/instant messenger
- Source
- cve@mitre.org
References
- http://www.informationweek.com/story/IWK20010927S0021
- http://www.instantmessagingplanet.com/security/article.php/10818_1014151
- http://www.kb.cert.org/vuls/id/744139US Government Resource
- http://www.informationweek.com/story/IWK20010927S0021
- http://www.instantmessagingplanet.com/security/article.php/10818_1014151
- http://www.kb.cert.org/vuls/id/744139US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.