First published: Sun Jan 13 2002(Updated: )
Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0077 has a medium severity rating due to its potential for exploiting local executables.
To fix CVE-2002-0077, update to a later version of Microsoft Internet Explorer or apply the security patches provided by Microsoft.
CVE-2002-0077 affects Microsoft Internet Explorer versions 5.01, 5.5, and 6.0.
CVE-2002-0077 allows remote attackers to invoke executables on the local system through affected objects.
Using Internet Explorer 5.5 or earlier is not safe due to the vulnerabilities associated with CVE-2002-0077.