CVE-2002-0980
The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 26.67% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=102942234427691&w=2
- http://marc.info/?l=ntbugtraq&m=102937705527922&w=2
- http://marc.info/?l=vuln-dev&m=102943486811091&w=2
- http://www.iss.net/security_center/static/9881.php
- http://www.securityfocus.com/bid/5473
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-014
- http://marc.info/?l=bugtraq&m=102942234427691&w=2
- http://marc.info/?l=ntbugtraq&m=102937705527922&w=2
- http://marc.info/?l=vuln-dev&m=102943486811091&w=2
- http://www.iss.net/security_center/static/9881.php
- http://www.securityfocus.com/bid/5473
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-014
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.