CVE-2006-1190
Last modified
CVE-2006-1190 is a vulnerability of currently unknown severity. Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.. EPSS estimates a 61.29% chance of exploitation in the next 30 days.
Description
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Explorer | 5.01 |
| Microsoft | Internet Explorer | 5.1 |
| Microsoft | Internet Explorer | 5.5 |
| Microsoft | Internet Explorer | 6.0 |
References
- http://www.kb.cert.org/vuls/id/959649US Government Resource
- http://www.kb.cert.org/vuls/id/959649US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1190?
How severe is CVE-2006-1190?
How do I fix CVE-2006-1190?
Are you affected by CVE-2006-1190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
