AIM has a major security vulnerability in the latest stable (4.7.2480) and beta (4.8.2616) Windows versions. In addition, most versions prior to 4.7 are also vulnerable. Users of AIM Express and non-Windows versions are *NOT* vulnerable. This vulnerability will allow remote penetration of the victim's system without any indication as to who performed the attack. There is no opportunity to refuse the request. This does not affect the non-Windows versions, because the non-Windows versions currently do not yet support the feature that this vulnerability occurs in. This particular vulnerability results from an overflow in the code that parses a game request.
AOL fixed it on the server side. I imagine the next update will fix the client side as well.