First published: Mon May 07 2001(Updated: )
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | <=5.5 | |
Internet Explorer | =5.01 | |
Microsoft Windows Script Host | =5.1 | |
Microsoft Windows Script Host | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0002 is considered a critical vulnerability due to its ability to allow remote code execution.
To mitigate CVE-2001-0002, users should upgrade to a later version of Internet Explorer or apply appropriate security patches from Microsoft.
CVE-2001-0002 affects Internet Explorer versions 5.5 and earlier, including version 5.01.
Yes, CVE-2001-0002 can be exploited by remote attackers to execute arbitrary programs on a vulnerable system.
Compiled HTML help (.chm) files can be leveraged in the attacks associated with CVE-2001-0002.