CVE-2006-4494
Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.
- Affected products
- Internet Explorer, Visual Studio
- Microsoft Visual Studio
- = 6.0
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 22.1% (98th percentile)
- NVD status
- Modified
- Published
- 2006-08-31
CVE-2006-4494 at NVD
1 known exploit for CVE-2006-4494
Proof-of-concept code and exploit modules indexed by Sploitus