Vulnerability Name: | CVE-2005-3240 (CCN-24648) | ||||||||
Assigned: | 2005-12-31 | ||||||||
Published: | 2005-12-31 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 3.8 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-362 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Mon Feb 13 2006 - 18:40:29 CST Advisory: Internet Explorer Drag and Drop Redeux [CVE-2005-3240] (fwd) Source: CCN Type: Microsoft Security Response Center Blog Monday, February 13, 2006 10:48 PM Information on IE Drag and Drop Issue Source: MISC Type: UNKNOWN http://blogs.technet.com/msrc/archive/2006/02/13/419439.aspx Source: MITRE Type: CNA CVE-2005-3240 Source: CCN Type: SA18787 Internet Explorer Drag-and-Drop Vulnerability Source: SECUNIA Type: Vendor Advisory 18787 Source: CCN Type: SECTRACK ID: 1015049 Microsoft Internet Explorer Drag-and-Drop Timing May Let Remote Users Install Arbitrary Files Source: SECTRACK Type: UNKNOWN 1015049 Source: OSVDB Type: UNKNOWN 2707 Source: CCN Type: OSVDB ID: 2707 Microsoft IE Drag and Drop Arbitrary File Installation Source: CCN Type: SecuriTeam Windows NT Focus 13 Feb. 2006 Microsoft Internet Explorer Drag-and-Drop Redeux Source: MISC Type: Vendor Advisory http://www.securiteam.com/windowsntfocus/5MP0B0UHPA.html Source: BUGTRAQ Type: UNKNOWN 20060213 Internet Explorer drag&drop 0day Source: BUGTRAQ Type: UNKNOWN 20060214 Advisory: Internet Explorer Drag and Drop Redeux [CVE-2005-3240] (fwd) Source: BID Type: UNKNOWN 16352 Source: CCN Type: BID-16352 Microsoft Internet Explorer Drag And Drop File Installation Vulnerability Variant Source: VUPEN Type: Vendor Advisory ADV-2006-0553 Source: CCN Type: IBM Internet Security Systems X-Force Database Microsoft Internet Explorer drag and drop event file downloading Source: XF Type: UNKNOWN ie-dragdrop-variant(24648) Source: XF Type: UNKNOWN ie-dragdrop-variant(24648) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |