Lucene search

K
cveMicrosoftCVE-2006-1190
HistoryApr 11, 2006 - 11:02 p.m.

CVE-2006-1190

2006-04-1123:02:00
microsoft
web.nvd.nist.gov
36
4
cve-2006-1190
microsoft internet explorer
ioleclientsite
security context
remote code execution
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

High

EPSS

0.891

Percentile

98.8%

Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.

Affected configurations

Nvd
Node
microsoftinternet_explorerMatch5.01
OR
microsoftinternet_explorerMatch5.1
OR
microsoftinternet_explorerMatch5.5
OR
microsoftinternet_explorerMatch6.0
VendorProductVersionCPE
microsoftinternet_explorer5.01cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
microsoftinternet_explorer5.1cpe:2.3:a:microsoft:internet_explorer:5.1:*:*:*:*:*:*:*
microsoftinternet_explorer5.5cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
microsoftinternet_explorer6.0cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

High

EPSS

0.891

Percentile

98.8%