CVE-2006-1190
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.
- Affected products
- Internet Explorer
- Microsoft Internet Explorer
- = 5.01, 5.1, 5.5, 6.0
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 61.3% (99th percentile)
- NVD status
- Modified
- Published
- 2006-04-11
CVE-2006-1190 at NVD
1 known exploit for CVE-2006-1190
Proof-of-concept code and exploit modules indexed by Sploitus