Vulnerability Name: | CVE-2004-2291 (CCN-14127) | ||||||||
Assigned: | 2004-01-01 | ||||||||
Published: | 2004-01-01 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Thu Jan 01 2004 - 16:41:35 CST Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part IV Source: CCN Type: Full-Disclosure Mailing List, Fri Jan 02 2004 - 21:14:46 CST RE: Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part IV Source: MITRE Type: CNA CVE-2004-2291 Source: CCN Type: OSVDB ID: 7913 Microsoft IE Shell.Application ActiveX Arbitrary Command Execution Source: BUGTRAQ Type: Exploit, Vendor Advisory 20040101 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part Source: BID Type: Exploit 9335 Source: CCN Type: BID-9335 Microsoft Internet Explorer Malicious Shortcut Self-Executing HTML Vulnerability Source: XF Type: UNKNOWN ie-lnk-code-execution(14127) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |