First published: Tue Jun 27 2000(Updated: )
Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =4.0.1-sp2 | |
Internet Explorer | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2000-0596 is considered high due to its potential to allow remote attackers to execute arbitrary commands.
To fix CVE-2000-0596, upgrade to a later version of Internet Explorer or disable the use of ActiveX controls.
CVE-2000-0596 affects Internet Explorer versions 4.0.1 with service pack 2 and all versions of 5.x.
CVE-2000-0596 enables the execution of arbitrary commands through an unprotected Microsoft Access database file when opened via ActiveX OBJECT tags.
A temporary workaround for CVE-2000-0596 is to adjust security settings in Internet Explorer to prompt before executing ActiveX controls.