First published: Wed Dec 14 2005(Updated: )
Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Internet Explorer | =5.0.1-sp4 | |
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2829 is considered to have a critical severity rating due to allowing arbitrary code execution.
Fixing CVE-2005-2829 involves upgrading to a supported version of Microsoft Internet Explorer or applying relevant security patches.
CVE-2005-2829 affects Internet Explorer versions 5.01, 5.5, and 6.0.
CVE-2005-2829 facilitates user-assisted attacks that could lead to the execution of arbitrary code.
Yes, exploiting CVE-2005-2829 requires user interaction.