CVE-2006-1303: Code Injection
Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1303?
CVE-2006-1303 is categorized as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-1303?
To fix CVE-2006-1303, it is recommended to update Microsoft Internet Explorer to the latest version or apply the necessary security patches.
Which versions of Microsoft Internet Explorer are affected by CVE-2006-1303?
CVE-2006-1303 affects Microsoft Internet Explorer 5.01 SP4 and 6.0 SP1, as well as earlier versions.
What type of vulnerability is CVE-2006-1303?
CVE-2006-1303 is a remote code execution vulnerability that can be exploited by attackers through ActiveX controls.
Who is at risk from CVE-2006-1303?
Users running vulnerable versions of Microsoft Internet Explorer are at risk of exploitation from attackers.