First published: Sat May 13 2000(Updated: )
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0400 has a moderate severity level as it allows file downloads without restrictions, potentially leading to malicious content execution.
To fix CVE-2000-0400, users should upgrade to a newer version of Internet Explorer that does not contain this vulnerability.
CVE-2000-0400 allows the download of any file type, enabling attackers to deliver harmful payloads.
CVE-2000-0400 specifically affects Internet Explorer version 5.
Yes, CVE-2000-0400 can be exploited by encoding malicious files within email messages.