CVE-2006-1186
UnknownEPSS 57.93%
Last modified
CVE-2006-1186 is a vulnerability of currently unknown severity. Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.. EPSS estimates a 57.93% chance of exploitation in the next 30 days.
Description
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Ie | 5.0.1 | — |
| Microsoft | Ie | 5.01 | Windows 2000 Sp4 |
| Microsoft | Ie | 6 | Windows Server 2003 Sp1 |
| Microsoft | Internet Explorer | 5.0.1 | — |
| Microsoft | Internet Explorer | 5.01 | — |
| Microsoft | Internet Explorer | 5.1 | — |
| Microsoft | Internet Explorer | 5.5 | — |
References
- http://secunia.com/advisories/18957Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/959049US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA06-101A.htmlUS Government Resource
- http://secunia.com/advisories/18957Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/959049US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA06-101A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1186?
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.
How severe is CVE-2006-1186?
Severity scoring for CVE-2006-1186 is pending analysis. The EPSS model estimates a 57.93% probability of exploitation in the next 30 days.
How do I fix CVE-2006-1186?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-1176Buffer overflow in eBay Enhanced Picture Services (aka EPUIm…
- CVE-2006-1178Tamarack MMSd before 7.992 allows remote attackers to cause …
- CVE-2006-1182Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and A…
- CVE-2006-1183The Ubuntu 5.10 installer does not properly clear passwords …
- CVE-2006-1184Microsoft Distributed Transaction Coordinator (MSDTC) for Wi…
- CVE-2006-1185Unspecified vulnerability in Microsoft Internet Explorer 5.0…
- CVE-2006-1187Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2006-1188Microsoft Internet Explorer 5.01 through 6 allows remote att…
- CVE-2006-1189Buffer overflow in URLMON.DLL in Microsoft Internet Explorer…
- CVE-2006-1190Microsoft Internet Explorer 5.01 through 6 does not always r…
- CVE-2006-1191Microsoft Internet Explorer 5.01 through 6 does not always c…
- CVE-2006-1192Microsoft Internet Explorer 5.01 through 6 allows remote att…
Are you affected by CVE-2006-1186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
