CVE-2011-10027 Details
Description
AOL Desktop 9.6 contains a buffer overflow vulnerability in its Tool\rich.rct component when parsing .rtx files. By embedding an overly long string in a hyperlink tag, an attacker can trigger a stack-based buffer overflow due to the use of unsafe strcpy operations. This allows remote attackers to execute arbitrary code when a victim opens a malicious .rtx file. AOL Desktop is end-of-life and no longer supported. Users are encouraged to migrate to AOL Desktop Gold or alternative platforms.
A stack-based buffer overflow vulnerability has been identified in AOL Desktop 9.6. The issue arises in the Tool\rich.rct component when the application processes .rtx files. An attacker can exploit this vulnerability by embedding an excessively long string in a hyperlink tag, which leads to a buffer overflow due to the use of unsafe string copy operations. This vulnerability allows remote attackers to execute arbitrary code on the victim's system when the malicious .rtx file is opened.
AOL Desktop 9.6 is no longer supported, and users are advised to upgrade to AOL Desktop Gold or consider alternative platforms.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/aol_desktop_linktag.rb | [email protected] | ExploitMetasploit Framework (MSF) |
| https://www.exploit-db.com/exploits/16085 | [email protected] | Exploit |
| https://www.exploit-db.com/exploits/16107 | [email protected] | Exploit |
| https://www.exploit-db.com/exploits/17150 | [email protected] | ExploitMetasploit Framework (MSF) |
| https://www.fortiguard.com/encyclopedia/ips/26516 | [email protected] | Advisory |
| https://www.vulncheck.com/advisories/aol-desktop-rtx-stack-based-buffer-overflow | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AOL Desktop | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | New CVE Received | [email protected] |
Volerion