CVE-2006-2385: Code Injection
Published Jun 13, 2006
·Updated
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.
Affected Software
2 affected components
Microsoft ie=6.0-sp1
Microsoft Internet Explorer=5.01-sp4
Event History
Jun 13, 2006
CVE Published
07:06 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2385?
The severity of CVE-2006-2385 is considered high due to the potential for remote code execution.
2
How do I fix CVE-2006-2385?
To fix CVE-2006-2385, users should upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.
3
What software is affected by CVE-2006-2385?
CVE-2006-2385 affects Microsoft Internet Explorer 5.01 SP4 and 6 SP1.
4
Can CVE-2006-2385 be exploited without user interaction?
CVE-2006-2385 requires user interaction, as the attacker must lure the user to a malicious web page.
5
What type of vulnerability is CVE-2006-2385?
CVE-2006-2385 is a memory corruption vulnerability that can lead to arbitrary code execution.