PT-2006-4175 · Microsoft · Windows Explorer+2
Plebo Aesdi Nael
·
Published
2006-06-28
·
Updated
2021-07-23
·
CVE-2006-3281
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer version 6.0
Windows Explorer (affected versions not specified)
Description
The issue arises from the improper handling of Drag and Drop events, allowing remote user-assisted attackers to execute arbitrary code. This can be achieved via a link to an SMB file share with a filename containing encoded .. (%2e%2e%5c) sequences and an extension that includes the CLSID Key identifier for HTML Applications (HTA). An attacker could exploit this by constructing a malicious Web page, potentially allowing them to save a file on the user's system if the user visits a malicious Web site or views a malicious e-mail message. Successful exploitation could grant the attacker complete control of the affected system, requiring user interaction.
Recommendations
For Microsoft Internet Explorer version 6.0, update to a newer version to mitigate the risk.
For Windows Explorer, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Windows
Windows Explorer