CVE-2007-3833
The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full…
Does this matter?
Lower severity and a low EPSS score (2.60%). Track it; it rarely justifies an emergency change on its own.
Description
The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full pathname in the ini field. NOTE: this can be leveraged for code execution by writing to a Startup folder.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.60% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- cerulean studios/trillian
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/26086
- http://www.securityfocus.com/bid/24927Exploit
- http://www.vupen.com/english/advisories/2007/2546
- http://www.xs-sniper.com/nmcfeters/Cross-App-Scripting-2.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35449
- http://secunia.com/advisories/26086
- http://www.securityfocus.com/bid/24927Exploit
- http://www.vupen.com/english/advisories/2007/2546
- http://www.xs-sniper.com/nmcfeters/Cross-App-Scripting-2.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35449
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.