CVE-2006-4495
Microsoft Windows Server 2000 - Multiple COM Object Instantiation Code Execution Vulnerabilities
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
Microsoft Internet Explorer permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria) y posiblemente ejecutar código de su elección instanciando ciertos objetos Windows 2000 ActiveX COM incluyendo (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, y (4) creator.dll.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-08-21 First Exploit
- 2006-08-31 CVE Reserved
- 2006-08-31 CVE Published
- 2023-10-27 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/1474 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/443896/100/100/threaded | Mailing List | |
http://www.securityfocus.com/bid/19636 | Vdb Entry | |
http://www.xsec.org/index.php?module=Releases&act=view&type=1&id=16 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28512 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28420 | 2006-08-21 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Ie Search vendor "Microsoft" for product "Ie" | 6.0 Search vendor "Microsoft" for product "Ie" and version "6.0" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | 2000_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "2000_server" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | 2000_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "2000_server" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | 2000_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "2000_server" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | 2000_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "2000_server" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | 2000_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "2000_server" | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | advanced_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "advanced_server" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | advanced_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "advanced_server" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | advanced_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "advanced_server" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | advanced_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "advanced_server" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | advanced_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "advanced_server" | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_server" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_server" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_server" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_server" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_server Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_server" | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | professional Search vendor "Microsoft" for product "Windows 2003 Server" and version "professional" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | professional Search vendor "Microsoft" for product "Windows 2003 Server" and version "professional" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | professional Search vendor "Microsoft" for product "Windows 2003 Server" and version "professional" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | professional Search vendor "Microsoft" for product "Windows 2003 Server" and version "professional" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | professional Search vendor "Microsoft" for product "Windows 2003 Server" and version "professional" | sp4 |
Affected
|