As mentioned in my last post, I have some very backlogged projects I’ve decided to just release to get them out of my backlog. This one is related to AOL Desktop Gold, the modern successor to the AOL desktop software a lot of us remember from the 90s. Yes it does still exist (and hence I had to look at it!)
This was a small group effort by Bruno, Chance, Joseph.Cohen.BT, and Jon “GainSec” Gaines. We spent a few hours looking at AOL Desktop Gold and ended up with a small set of interesting findings, proof-of-concept files, and evidence media.
The release includes the public write-up, PoCs, selected screenshots, and proof videos. The findings cover things like preference abuse, signed payload execution paths, EditorHost local file access, NTLMv2 hash capture, attachment preview injection, BinaryFormatter import behavior, .AolSave path traversal, toolbar command execution, SSRF, and local file disclosure through AOL-specific schemes.
We originally submitted CVE requests to MITRE on October 24, 2025, and reached out to AOL by email on January 12, 2026. We did not hear back from either. It has been a long time, and AOL Desktop Gold has likely been updated, so we determined it is time to release the information.
Nothing groundbreaking, but some cool stuff.
You can find it HERE
END TRANSMISSION
