PT-2006-2397 · Microsoft · Internet Explorer

Jeffrey Van Der Stad

·

Published

2006-03-24

·

Updated

2021-07-23

·

CVE-2006-1388

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer version 6.0
Description The issue allows remote attackers to execute HTA files, potentially enabling remote code execution. An HTML Application (HTA) can bypass Internet Explorer's security control, executing without displaying the normal security dialog box. If a user visits a malicious website, an attacker could exploit this issue, potentially taking complete control of the affected system.
Recommendations For Microsoft Internet Explorer version 6.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1388

Affected Products

Internet Explorer