CVE-2000-0400: Input Validation
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the Microsoft Active Movie ActiveX Control in Internet Explorer 5 to prevent it from downloading arbitrary file types.
Microsoft Active Movie ActiveX Control (Internet Explorer 5) ActiveX control enabled = disabled - Compensating control
At the mail/news gateway or proxy, filter or block messages and news posts containing encoded attachments and scan/strip suspicious encoded content to prevent delivery of files that could be downloaded via the ActiveX control.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0400?
CVE-2000-0400 has a moderate severity level as it allows file downloads without restrictions, potentially leading to malicious content execution.
How do I fix CVE-2000-0400?
To fix CVE-2000-0400, users should upgrade to a newer version of Internet Explorer that does not contain this vulnerability.
What types of files can be downloaded due to CVE-2000-0400?
CVE-2000-0400 allows the download of any file type, enabling attackers to deliver harmful payloads.
Which version of Internet Explorer is affected by CVE-2000-0400?
CVE-2000-0400 specifically affects Internet Explorer version 5.
Can CVE-2000-0400 be exploited through email messages?
Yes, CVE-2000-0400 can be exploited by encoding malicious files within email messages.