First published: Sat Dec 31 2005(Updated: )
Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Internet Explorer | =5.01 | |
Internet Explorer | =5.01-sp1 | |
Internet Explorer | =5.01-sp2 | |
Internet Explorer | =5.01-sp3 | |
Internet Explorer | =5.01-sp4 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3240 is considered a critical vulnerability due to its potential to allow arbitrary file overwriting and code execution.
To mitigate CVE-2005-3240, users should upgrade to a patched version of Internet Explorer or utilize alternative browsers.
CVE-2005-3240 affects multiple versions of Internet Explorer, including 5.01, 5.5, and 6.0, along with their respective service packs.
CVE-2005-3240 enables attackers to conduct user-assisted attacks by tricking users into performing drag-and-drop actions.
Users can protect themselves from CVE-2005-3240 by avoiding suspicious links and being cautious with actions involving drag-and-drop functionality.