Vulnerabilities > CVE-2001-0002 - Unspecified vulnerability in Microsoft Internet Explorer and Windows Script Host

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft

Summary

Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.

Vulnerable Configurations

Part Description Count
Application
Microsoft
62

Oval

accepted2014-02-24T04:03:28.132-05:00
classvulnerability
contributors
  • nameTiffany Bergeron
    organizationThe MITRE Corporation
  • nameMaria Mikhno
    organizationALTX-SOFT
descriptionInternet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
familywindows
idoval:org.mitre.oval:def:920
statusaccepted
submitted2004-04-29T12:00:00.000-04:00
titleIE Cached Content Command Execution Vulnerability
version66