Vulnerabilities > CVE-2006-4495 - COM Object Instantiation Code Execution vulnerability in Microsoft Windows 2000

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.

Exploit-Db

descriptionMicrosoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities. CVE-2006-4495. Dos exploit for windows platform
idEDB-ID:28420
last seen2016-02-03
modified2006-08-21
published2006-08-21
reporternop
sourcehttps://www.exploit-db.com/download/28420/
titleMicrosoft Windows 2000 - Multiple COM Object Instantiation Code Execution Vulnerabilities