First published: Mon May 07 2001(Updated: )
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | <=5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0150 is a critical vulnerability that allows remote attackers to execute arbitrary commands via a vulnerable Telnet session.
To mitigate CVE-2001-0150, users should upgrade to a later version of Internet Explorer or disable any Telnet client depending on the affected version.
CVE-2001-0150 affects users of Internet Explorer 5.5 and earlier who have the Telnet client from Services for Unix 2.0.
CVE-2001-0150 is associated with command injection attacks that can lead to arbitrary code execution.
Yes, CVE-2001-0150 can be exploited remotely by attackers leveraging crafted web pages.