First published: Tue Oct 30 2001(Updated: )
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | <=6.0 | |
Microsoft Internet Explorer | <=6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0667 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2001-0667, it is recommended to upgrade to a later version of Internet Explorer that is not affected.
Users of Internet Explorer 6 and earlier, especially in conjunction with the Telnet client in Services for Unix, are affected by CVE-2001-0667.
CVE-2001-0667 allows remote attackers to execute arbitrary commands on the affected system.
Although CVE-2001-0667 pertains to outdated software, any remaining systems still using Internet Explorer 6 may still be vulnerable and require attention.