First published: Tue Apr 11 2006(Updated: )
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.01 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-1190 is classified as critical due to the potential for remote code execution.
To fix CVE-2006-1190, users should upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.
CVE-2006-1190 affects Microsoft Internet Explorer versions 5.01, 5.5, 5.1, and 6.0.
Exploiting CVE-2006-1190 could allow an attacker to execute arbitrary code on the affected system.
A workaround for CVE-2006-1190 includes disabling scripting features within Internet Explorer.