CVE-2006-1190: Critical severity Microsoft Internet Explorer vulnerability
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1190?
The severity of CVE-2006-1190 is classified as critical due to the potential for remote code execution.
How do I fix CVE-2006-1190?
To fix CVE-2006-1190, users should upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.
What systems are affected by CVE-2006-1190?
CVE-2006-1190 affects Microsoft Internet Explorer versions 5.01, 5.5, 5.1, and 6.0.
What are the possible consequences of exploiting CVE-2006-1190?
Exploiting CVE-2006-1190 could allow an attacker to execute arbitrary code on the affected system.
Is there a workaround for CVE-2006-1190?
A workaround for CVE-2006-1190 includes disabling scripting features within Internet Explorer.