Risk: High
AOL 7.x, 8.x and 9.x have a vulnerability that could compromise a user's system if exploited.
The vulnerability is caused due to a boundary error within the "CDDBControlAOL.CDDBAOLControl" ActiveX control (cddbcontrol.dll) when processing the first argument passed to the "SetClientInfo()" method. This error can be exploited to cause a stack-based buffer overflow by passing an overly long string (more than 256 bytes). Successful exploitation allows execution of arbitrary code when a user visits a malicious website with Internet Explorer.
Updates are available for those AOL 9.x users when logging into an AOL account; any earlier versions should be updated immediately.