CVE-2006-3643
Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 20.49% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/ie · microsoft/internet explorer
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/21401
- http://securitytracker.com/id?1016655
- http://www.kb.cert.org/vuls/id/927548Patch, US Government Resource
- http://www.securityfocus.com/bid/19417
- http://www.us-cert.gov/cas/techalerts/TA06-220A.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2006/3213
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-044
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28005
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A638
- http://secunia.com/advisories/21401
- http://securitytracker.com/id?1016655
- http://www.kb.cert.org/vuls/id/927548Patch, US Government Resource
- http://www.securityfocus.com/bid/19417
- http://www.us-cert.gov/cas/techalerts/TA06-220A.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2006/3213
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-044
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28005
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A638
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.