PT-2004-1998 · Microsoft · Internet Explorer

Published

2004-10-26

·

Updated

2017-07-11

·

CVE-2004-0985

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Internet Explorer version 6.x
Description: The issue allows remote attackers to execute arbitrary code. This can be achieved by using a document with a draggable file type, such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and utilizing ADODB.Connection and ADODB.recordset to write to a .hta file. The .hta file is then interpreted in the Local Zone by HTML Help.
Recommendations: For Internet Explorer version 6.x, consider disabling the use of ADODB.Connection and ADODB.recordset to mitigate the risk of arbitrary code execution until a patch is available. Restrict access to draggable file types to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0985

Affected Products

Internet Explorer