First published: Fri Aug 18 2006(Updated: )
The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4219 is rated as a high severity vulnerability due to its potential for denial of service and arbitrary code execution.
To mitigate CVE-2006-4219, users should uninstall Internet Explorer 6.0 SP1 or upgrade to a later, secure version of Internet Explorer.
CVE-2006-4219 specifically affects Microsoft Internet Explorer 6.0 SP1 on Windows 2003 EE SP1.
CVE-2006-4219 can be exploited by remote attackers to cause a denial of service and potentially execute arbitrary code through ActiveX instantiation.
A possible workaround for CVE-2006-4219 includes disabling ActiveX controls in Internet Explorer.