Vulnerability record · CVE-2004-0636 · published 23 November 2004
CVE-2004-0636: AOL Instant Messenger goaway URI handler buffer overflow
Aol · Instant Messenger
The aim:goaway URI handler in AOL Instant Messenger 5.5 (including 5.5.3595) contains a buffer overflow in its goaway function. A remote attacker can trigger it by supplying an overly long Away message, which can lead to arbitrary code execution on the victim's machine. The flaw matters because AIM was widely deployed and the handler is reachable from a URI, so the attack can be delivered without the victim running a separate program.
Description
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with complete impact and a very high EPSS score, but the record lacks KEV listing and confirmed in-the-wild exploitation.
What it is
The aim:goaway URI handler in AOL Instant Messenger 5.5 (including 5.5.3595) contains a buffer overflow in its goaway function. A remote attacker can trigger it by supplying an overly long Away message, which can lead to arbitrary code execution on the victim's machine. The flaw matters because AIM was widely deployed and the handler is reachable from a URI, so the attack can be delivered without the victim running a separate program.
Impact
An attacker who triggers the overflow can execute arbitrary code in the context of the AIM client, giving full control of the affected user's session and data. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.
Attack surface
The flaw is reached through the aim:goaway URI handler, meaning a crafted URI or message containing a long Away message is processed by the AIM client. The CVSS 2.0 vector (AV:N/AC:L/Au:N) indicates network reachability with no authentication required, though the record does not state whether user interaction is needed to open the URI.
Exploitation
The record is not listed in CISA KEV and contains no exploit tags, but EPSS gives a 30-day probability of 0.66019 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity. No public exploit code or in-the-wild confirmation is provided in the record.
What to do
- Apply the vendor patch referenced in the Secunia and iDefense advisories, or upgrade AIM to a fixed release.
- If AIM 5.5 cannot be patched, remove or disable the aim:goaway URI handler registration so crafted URIs are not passed to the client.
- Block or filter aim: URI schemes and suspicious Away-message content at email and web gateways.
- Retire AIM 5.5 where possible, since the product is long end-of-life and no longer receives security fixes.
Detection
- Monitor for AIM client crashes or abnormal process termination that could indicate a malformed goaway message.
- Inspect email and web content for aim:goaway URIs with unusually long Away message parameters.
- Watch for unexpected child processes or network connections spawned by the AIM client process.
- Review endpoint logs for AIM 5.5 execution alongside suspicious URI handler invocations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://secunia.com/advisories/12198/ | PatchVendor Advisory |
| http://www.idefense.com/application/poi/display?id=121&type=vulnerabilities | PatchVendor Advisory |
| http://www.kb.cert.org/vuls/id/735966 | US Government Resource |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/16926 | |
| http://secunia.com/advisories/12198/ | PatchVendor Advisory |
| http://www.idefense.com/application/poi/display?id=121&type=vulnerabilities | PatchVendor Advisory |
| http://www.kb.cert.org/vuls/id/735966 | US Government Resource |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/16926 |
Track CVE-2004-0636 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0636), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.