Vulnerability Name:

CVE-2005-3240 (CCN-24648)

Assigned:2005-12-31
Published:2005-12-31
Updated:2021-07-23
Summary:Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window.
CVSS v3 Severity:9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.6 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-362
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-Disclosure Mailing List, Mon Feb 13 2006 - 18:40:29 CST
Advisory: Internet Explorer Drag and Drop Redeux [CVE-2005-3240] (fwd)

Source: CCN
Type: Microsoft Security Response Center Blog Monday, February 13, 2006 10:48 PM
Information on IE Drag and Drop Issue

Source: MISC
Type: UNKNOWN
http://blogs.technet.com/msrc/archive/2006/02/13/419439.aspx

Source: MITRE
Type: CNA
CVE-2005-3240

Source: CCN
Type: SA18787
Internet Explorer Drag-and-Drop Vulnerability

Source: SECUNIA
Type: Vendor Advisory
18787

Source: CCN
Type: SECTRACK ID: 1015049
Microsoft Internet Explorer Drag-and-Drop Timing May Let Remote Users Install Arbitrary Files

Source: SECTRACK
Type: UNKNOWN
1015049

Source: OSVDB
Type: UNKNOWN
2707

Source: CCN
Type: OSVDB ID: 2707
Microsoft IE Drag and Drop Arbitrary File Installation

Source: CCN
Type: SecuriTeam Windows NT Focus 13 Feb. 2006
Microsoft Internet Explorer Drag-and-Drop Redeux

Source: MISC
Type: Vendor Advisory
http://www.securiteam.com/windowsntfocus/5MP0B0UHPA.html

Source: BUGTRAQ
Type: UNKNOWN
20060213 Internet Explorer drag&drop 0day

Source: BUGTRAQ
Type: UNKNOWN
20060214 Advisory: Internet Explorer Drag and Drop Redeux [CVE-2005-3240] (fwd)

Source: BID
Type: UNKNOWN
16352

Source: CCN
Type: BID-16352
Microsoft Internet Explorer Drag And Drop File Installation Vulnerability Variant

Source: VUPEN
Type: Vendor Advisory
ADV-2006-0553

Source: CCN
Type: IBM Internet Security Systems X-Force Database
Microsoft Internet Explorer drag and drop event file downloading

Source: XF
Type: UNKNOWN
ie-dragdrop-variant(24648)

Source: XF
Type: UNKNOWN
ie-dragdrop-variant(24648)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:internet_explorer:5.01:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.01:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.01:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:-:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft internet explorer 5.01 sp3
    microsoft internet explorer 5.01 sp4
    microsoft internet explorer 5.01
    microsoft internet explorer 5.5 sp2
    microsoft internet explorer 6.0
    microsoft internet explorer 5.01 sp1
    microsoft internet explorer 5.01 sp2
    microsoft ie 6.0 sp1
    microsoft internet explorer 5.5
    microsoft internet explorer 5.5 sp1
    microsoft ie 5.01
    microsoft ie 5.5
    microsoft ie 6.0