Vulnerability Name:

CVE-2004-2291 (CCN-14127)

Assigned:2004-01-01
Published:2004-01-01
Updated:2021-07-23
Summary:Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-Disclosure Mailing List, Thu Jan 01 2004 - 16:41:35 CST
Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part IV

Source: CCN
Type: Full-Disclosure Mailing List, Fri Jan 02 2004 - 21:14:46 CST
RE: Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part IV

Source: MITRE
Type: CNA
CVE-2004-2291

Source: CCN
Type: OSVDB ID: 7913
Microsoft IE Shell.Application ActiveX Arbitrary Command Execution

Source: BUGTRAQ
Type: Exploit, Vendor Advisory
20040101 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part

Source: BID
Type: Exploit
9335

Source: CCN
Type: BID-9335
Microsoft Internet Explorer Malicious Shortcut Self-Executing HTML Vulnerability

Source: XF
Type: UNKNOWN
ie-lnk-code-execution(14127)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:preview:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:internet_explorer:5.5:-:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft internet explorer 5.5 sp1
    microsoft internet explorer 5.5
    microsoft internet explorer 5.5 preview
    microsoft internet explorer 6.0
    microsoft internet explorer 5.5 sp2
    microsoft ie 6.0 sp1
    microsoft ie 5.5
    microsoft ie 6.0