CVE-2004-0985
Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to write to a .hta file that is interpreted in the Local Zone by HTML Help.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 20.24% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/ie
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109829111200055&w=2
- http://marc.info/?l=bugtraq&m=109830296130857&w=2
- http://marc.info/?l=ntbugtraq&m=109828076802478&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17824
- http://marc.info/?l=bugtraq&m=109829111200055&w=2
- http://marc.info/?l=bugtraq&m=109830296130857&w=2
- http://marc.info/?l=ntbugtraq&m=109828076802478&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17824
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.