vendor:
Internet Explorer
by:
nop
7.5
CVSS
HIGH
Memory-corruption vulnerability
119
CWE
Product Name: Internet Explorer
Affected Version From: Microsoft Internet Explorer 5.01
Affected Version To: Microsoft Internet Explorer 6.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:microsoft:internet_explorer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2005
Microsoft Windows 2003 (tsuserex.dll) COM Object Instantiation Vulnerability
Attackers may exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. Exploitation attempts may lead to a denial-of-service condition as well. Attackers may also employ HTML email to carry out an attack.
Mitigation:
Ensure that all Microsoft Internet Explorer users are running the latest version of the software.