SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3833

The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full…

MEDIUM 5.0EPSS 2.60%

Does this matter?

Lower severity and a low EPSS score (2.60%). Track it; it rarely justifies an emergency change on its own.

Description

The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full pathname in the ini field. NOTE: this can be leveraged for code execution by writing to a Startup folder.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
2.60% probability · 84th percentile
CISA KEV
Not listed
Affected
cerulean studios/trillian
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.