CVE-2006-4697: Critical severity Microsoft Windows 2000 vulnerability
Published Feb 13, 2007
·Updated
Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.
Affected Software
13 affected components
Microsoft Windows 2000=sp4
Microsoft Internet Explorer=5.01-sp4
Microsoft ie=6.0-sp1
Microsoft Windows 2003 Server=gold
Microsoft Windows 2003 Server=gold
Microsoft Windows 2003 Server=gold
Microsoft Windows 2003 Server=sp1
Microsoft Windows 2003 Server=sp1
Microsoft Windows XP=sp2
Microsoft Windows XP=sp2
Microsoft Internet Explorer=6.0
Microsoft Windows XP=gold
Microsoft Internet Explorer=7.0
Event History
Feb 13, 2007
CVE Published
10:28 PM
Data Sourced
10:28 PM
DescriptionWeaknessAffected Software
Feb 14, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4697?
CVE-2006-4697 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2006-4697?
To mitigate CVE-2006-4697, it is recommended to update Internet Explorer to the latest supported version and apply all relevant security patches.
3
What versions of Internet Explorer are affected by CVE-2006-4697?
CVE-2006-4697 affects Microsoft Internet Explorer versions 5.01, 6, and 7.
4
Can CVE-2006-4697 be exploited remotely?
Yes, CVE-2006-4697 can be exploited remotely by attackers to execute arbitrary code.
5
Is Windows XP affected by CVE-2006-4697?
Yes, Windows XP is vulnerable to CVE-2006-4697 if it is running an affected version of Internet Explorer.