🔐 CVE Alert

CVE-2011-10027

UNKNOWN 0.0

AOL Desktop 9.6 RTX Stack-Based Buffer Overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

AOL Desktop 9.6 contains a buffer overflow vulnerability in its Tool\rich.rct component when parsing .rtx files. By embedding an overly long string in a hyperlink tag, an attacker can trigger a stack-based buffer overflow due to the use of unsafe strcpy operations. This allows remote attackers to execute arbitrary code when a victim opens a malicious .rtx file. AOL Desktop is end-of-life and no longer supported. Users are encouraged to migrate to AOL Desktop Gold or alternative platforms.

CWE CWE-121
Vendor aol inc.
Product aol desktop
Published Aug 20, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for aol inc. aol desktop

Be the first to know when new unknown vulnerabilities affecting aol inc. aol desktop are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

AOL Inc. / AOL Desktop
* ≤ 9.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/aol_desktop_linktag.rb exploit-db.com: https://www.exploit-db.com/exploits/16085 exploit-db.com: https://www.exploit-db.com/exploits/16107 exploit-db.com: https://www.exploit-db.com/exploits/17150 fortiguard.com: https://www.fortiguard.com/encyclopedia/ips/26516 vulncheck.com: https://www.vulncheck.com/advisories/aol-desktop-rtx-stack-based-buffer-overflow

Credits

sup3r