First published: Thu Sep 20 2001(Updated: )
Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0643 has a medium severity rating due to its potential to trick users into executing harmful programs.
To mitigate CVE-2001-0643, it is recommended to upgrade to a more recent version of Internet Explorer or use a different web browser.
CVE-2001-0643 enables social engineering attacks by disguising harmful files as safe file types.
CVE-2001-0643 specifically affects Internet Explorer version 5.5.
Yes, CVE-2001-0643 can still pose a risk since it relies on user interaction for execution, making antivirus software less effective.