vendor:
Internet Explorer
by:
Frsirt
9,3
CVSS
HIGH
COM Object Exploit
94
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 5.01 Service Pack 3 on Microsoft Windows 2000 Service Pack 3
Affected Version To: Internet Explorer 6 on Windows Server 2003 with SP1 for 64-Bit Itanium-based Systems
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2000, Windows XP, Windows Server 2003
2005
Microsoft Internet Explorer javaprxy.dll COM Object Exploit -Unpatched-
This exploit allows an attacker to gain remote access to a vulnerable system by exploiting a vulnerability in the javaprxy.dll COM object. The vulnerability is present in multiple versions of Internet Explorer, including IE 5.01 SP3 and SP4 on Windows 2000 SP3 and SP4, IE 6 SP1 on Windows 2000 SP3 and SP4, IE 6 SP1 on Windows XP SP1, IE 6 on Windows XP SP2, IE 6 SP1 on Windows XP 64-Bit SP1 (Itanium), IE 6 on Windows Server 2003, IE 6 on Windows Server 2003 SP1, IE 6 on Windows Server 2003 for Itanium-based Systems, IE 6 on Windows XP 64-Bit Edition Version 2003 (Itanium), IE 6 on Windows Server 2003 x64 Edition, and IE 6 on Windows Server 2003 with SP1 for 64-Bit Itanium-based Systems.
Mitigation:
Set Internet and Local intranet security zone settings to 'High' or use another browser until a patch is released.