CVE-2006-3281

Description

Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded .. (%2e%2e%5c) sequences and whose extension contains the CLSID Key identifier for HTML Applications (HTA), aka Folder GUID Code Execution Vulnerability. NOTE: directory traversal sequences were used in the original exploit, although their role is not clear.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
62.708

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows 2000 (KB921398)Windows
Security Update for Windows XP (KB921398)Windows
Security Update for Windows Server 2003 (KB921398) x86 based systemsWindows
Security Update for Windows Server 2003 (KB921398) x86 based systems for SP1Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234