Vulnerability Name:

CVE-2006-3730 (CCN-27804)

Assigned:2006-07-18
Published:2006-07-18
Updated:2021-07-23
Summary:Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
CVSS v3 Severity:9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.6 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
6.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-94
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Wed Sep 27 2006 - 11:41:15 CDT
Exploit module available for WebViewFolderIcon setSlice 0-day

Source: CCN
Type: Browser Fun Blog Tuesday, July 18, 2006
MoBB #18: WebViewFolderIcon setSlice

Source: MISC
Type: Exploit
http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html

Source: MITRE
Type: CNA
CVE-2006-3730

Source: MISC
Type: UNKNOWN
http://isc.sans.org/diary.php?storyid=1742

Source: MISC
Type: UNKNOWN
http://riosec.com/msie-setslice-vuln

Source: CCN
Type: SA22159
Microsoft Windows Shell Code Execution Vulnerability

Source: SECUNIA
Type: Vendor Advisory
22159

Source: CCN
Type: SECTRACK ID: 1016941
Microsoft Windows Shell Integer Overflow Lets Remote Users Execute Arbitrary Code

Source: SECTRACK
Type: UNKNOWN
1016941

Source: CCN
Type: ASA-2006-217
Windows Security Updates for October 2006 - (MS06-056 - MS06-065)

Source: CCN
Type: US-CERT VU#753044
Microsoft Windows WebViewFolderIcon ActiveX integer overflow

Source: CERT-VN
Type: US Government Resource
VU#753044

Source: CCN
Type: Microsoft Security Advisory (926043)
Vulnerability in Windows Shell Could Allow Remote Code Execution

Source: CCN
Type: Microsoft Security Bulletin MS06-057
Vulnerability in Windows Explorer Could Allow Remote Execution (923191)

Source: OSVDB
Type: UNKNOWN
27110

Source: CCN
Type: OSVDB ID: 27110
Microsoft IE WebViewFolderIcon setSlice Overflow

Source: BUGTRAQ
Type: UNKNOWN
20060927 Exploit module available for WebViewFolderIcon setSlice 0-day

Source: BUGTRAQ
Type: UNKNOWN
20060929 Determina zero-day fix for CVE-2006-3730 (WebViewFolderIcon setSlice Integer Overflow)

Source: BUGTRAQ
Type: UNKNOWN
20060930 setSlice exploited in the wild - massively

Source: BUGTRAQ
Type: UNKNOWN
20060930 ZERT patch for setSlice()

Source: HP
Type: UNKNOWN
SSRT061264

Source: BID
Type: Exploit
19030

Source: CCN
Type: BID-19030
Microsoft WebViewFolderIcon ActiveX Control Buffer Overflow Vulnerability

Source: CCN
Type: US-CERT Technical Cyber Security Alert TA06-270A
Microsoft Internet Explorer WebViewFolderIcon ActiveX Vulnerability

Source: CERT
Type: US Government Resource
TA06-270A

Source: CERT
Type: US Government Resource
TA06-283A

Source: VUPEN
Type: Vendor Advisory
ADV-2006-2882

Source: CCN
Type: Internet Security Systems Protection Alert October 3, 2006
Vulnerability in Windows Shell Could Allow Remote Code Execution

Source: MS
Type: UNKNOWN
MS06-057

Source: XF
Type: UNKNOWN
ie-webviewfoldericon-code-execution(27804)

Source: XF
Type: UNKNOWN
ie-webviewfoldericon-dos(27804)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:339

Source: EXPLOIT-DB
Type: UNKNOWN
2440

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server::x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:-::~~~~itanium~:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server:sp1_itanium:*:*:*:*:*:*
  • OR cpe:/a:microsoft:windows_2003:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:339
    V
    Windows Shell Remote Code Execution Vulnerability
    2011-05-09
    BACK
    microsoft internet explorer 6.0
    microsoft ie 6.0 sp1
    microsoft windows xp * sp2
    microsoft windows xp - sp1
    microsoft windows 2000 - sp4
    microsoft windows 2003_server
    microsoft windows xp sp2
    microsoft windows 2003 server -
    microsoft windows 2003_server sp1
    microsoft windows 2003_server sp1_itanium
    microsoft windows 2003 *