CVE-2004-2090: Medium severity Microsoft ie vulnerability
Published Feb 7, 2004
·Updated
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
Affected Software
10 affected components
Microsoft ie=6.0-sp1
Microsoft Internet Explorer=5.0.1
Microsoft Internet Explorer=5.0.1-sp1
Microsoft Internet Explorer=5.0.1-sp2
Microsoft Internet Explorer=5.0.1-sp3
Microsoft Internet Explorer=5.0.1-sp4
Microsoft Internet Explorer=5.5
Microsoft Internet Explorer=5.5-sp1
Microsoft Internet Explorer=5.5-sp2
Microsoft Internet Explorer=6.0
Event History
Feb 7, 2004
CVE Published
05:00 AM
May 19, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2090?
CVE-2004-2090 has been classified as a moderate severity vulnerability.
2
How does CVE-2004-2090 affect Microsoft Internet Explorer?
CVE-2004-2090 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method.
3
Which versions of Internet Explorer are affected by CVE-2004-2090?
CVE-2004-2090 affects Microsoft Internet Explorer versions from 5.0.1 through 6.0, including service packs.
4
How can I mitigate CVE-2004-2090?
To mitigate CVE-2004-2090, users should upgrade to a supported version of Internet Explorer or disable VBScript.
5
Is there a patch available for CVE-2004-2090?
There is no specific patch for CVE-2004-2090, so upgrading to a later version of Internet Explorer is recommended.