First published: Fri Aug 19 2005(Updated: )
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework 4 | =1.1-sp1 | |
Microsoft Visual Studio | =2003-gold | |
Microsoft Visio Standard | =2002-sp1 | |
Microsoft .NET Framework 4 | =1.1-sp2 | |
Microsoft Project 2013 | =2002-sp1 | |
Microsoft Project 2013 | =2003 | |
Microsoft Visio Standard | =2002 | |
Microsoft Office | =xp-sp3 | |
Microsoft Project 2013 | =2000 | |
Microsoft Visio Standard | =2003-sp1 | |
Microsoft Office | =2000 | |
AMD Catalyst Driver | ||
Microsoft Office | ||
Microsoft Project 2013 | =2002 | |
Microsoft Office | =xp-sp2 | |
Microsoft .NET Framework 4 | =1.1 | |
Microsoft Visio Standard | =2002-sp2 | |
Microsoft .NET Framework 4 | =1.1-sp3 | |
Microsoft Project 2013 | =98 | |
Microsoft Office | =2000-sp1 | |
Microsoft Project 2013 | =2003-sp1 | |
Microsoft Office | =2000-sp2 | |
Microsoft Visio Standard | =2003 | |
Microsoft Visual Studio | =2002-gold | |
Microsoft Office | =xp-sp1 | |
Microsoft Office | =2000-sp3 | |
Microsoft Office | =2000 | |
Microsoft Office | =2000 | |
Microsoft Office | =2000 | |
Microsoft Visio Standard | =2000-sr1 | |
Microsoft Visio Standard | =2002 | |
Microsoft Visio Standard | =2002-sp2 | |
Microsoft Visio Standard | =2002-sp2 | |
Microsoft Visio Standard | =2003 | |
Microsoft Visio Standard | =2003 | |
Microsoft Visual Studio | =2003 | |
Microsoft Visual Studio | =gold | |
Microsoft Visual Studio | =gold | |
Microsoft Visual Studio | =gold | |
Microsoft Visual Studio | =gold | |
Microsoft Visual Studio | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-2127 is categorized as high due to its potential for causing denial of service and executing arbitrary code.
To fix CVE-2005-2127, ensure that you install the latest security patches from Microsoft for affected Internet Explorer versions.
CVE-2005-2127 affects Microsoft Internet Explorer versions 5.01, 5.5, and 6.
CVE-2005-2127 can be exploited through a web page containing embedded CLSIDs that reference specific COM objects not intended for Internet Explorer.
Yes, CVE-2005-2127 has the potential to lead to data breaches as it may allow attackers to execute arbitrary code remotely.