CVE-2005-0053: High severity Microsoft ie vulnerability
Published Feb 8, 2005
·Updated
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
Affected Software
35 affected components
Microsoft ie=6.0-sp1
Microsoft ie=6.0-sp2
Microsoft Internet Explorer=5.5-sp2
Microsoft Internet Explorer=5.0.1
Microsoft Internet Explorer=5.0.1-sp2
Microsoft Internet Explorer=5.0.1-sp3
Microsoft Internet Explorer=5.0.1-sp4
Microsoft Internet Explorer=5.0.1-sp1
Microsoft Internet Explorer=5.5
Microsoft Internet Explorer=5.5-sp1
Microsoft Internet Explorer=6.0
Microsoft Windows XP=sp1
Microsoft Windows 2003 Server=web
Microsoft Windows 2003 Server=enterprise
Microsoft Windows 2003 Server=enterprise_64-bit
Microsoft Windows XP=gold
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows 2000=sp4
Microsoft Windows XP=sp2
Microsoft Windows XP
Microsoft Windows XP=sp1
Microsoft Windows 98SE
Microsoft Windows 2000=sp2
Microsoft Windows 2003 Server=r2
Microsoft Windows 2000=sp1
Microsoft Windows XP=sp2
Microsoft Windows XP
Microsoft Windows Me
Microsoft Windows XP=sp1
Microsoft Windows 2003 Server=standard
Microsoft Windows XP=sp2
Microsoft Windows 98=gold
Microsoft Windows 2003 Server=r2
Microsoft Windows 2000=sp3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 8, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0053?
CVE-2005-0053 is rated as a critical severity vulnerability due to its ability to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2005-0053?
To fix CVE-2005-0053, users should upgrade to the latest version of Internet Explorer or apply the relevant security updates provided by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2005-0053?
CVE-2005-0053 affects Internet Explorer versions 5.01, 5.5, and 6.x, including their service packs.
4
What exploit techniques are used in CVE-2005-0053?
CVE-2005-0053 exploits the drag and drop functionality in Internet Explorer to execute arbitrary code.
5
Is CVE-2005-0053 exploitable over the network?
Yes, CVE-2005-0053 can be exploited remotely without the user's knowledge via malicious web pages.