CVE-2004-0841
published 2004-12-23CVE-2004-0841: Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions…
PriorityP263medium5CVSS 2.0
AVNACLAuNCNIPAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
48.73%
98.7th percentile
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avaya | modular_messaging_message_storage_server | — | — |
| avaya | modular_messaging_message_storage_server | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for mousedown events invoking the Popup.show method in Internet Explorer, which may indicate exploitation of HijackClick 3 / Script in Image Tag File Download Vulnerability ↗
- →Watch for use of the shell: URI scheme (e.g., shell:favorites\) in browser-context location assignments, which is a technique used in the method-caching variant of this attack to drop or execute files ↗
- →Detect drag-and-drop interactions originating from popup windows spawned by Popup.show in Internet Explorer 6.x, as this is the core mechanism for hijacking user mouse events to approve dialogs or trigger downloads ↗
- ·The method-caching variant of this attack is also reported to work, meaning detection rules targeting only the direct Popup.show call may miss alternate exploitation paths ↗
- ·Affected scope includes Internet Explorer 5.0.1 in addition to IE 6.x; detections should not be scoped exclusively to IE 6 ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vulncheck5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fgjq-p2q2-66cx: Internet Explorer 6
ghsa_unreviewed·2022-04-29
CVE-2004-0841 [MEDIUM] GHSA-fgjq-p2q2-66cx: Internet Explorer 6
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
VulnCheck
Microsoft Internet Explorer Popup.show Method Vulnerability
vulncheck·2004·CVSS 5.0
CVE-2004-0841 [MEDIUM] Microsoft Internet Explorer Popup.show Method Vulnerability
Microsoft Internet Explorer Popup.show Method Vulnerability
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
Affected: avaya ip600_media_servers
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0498.htmlhttp://secunia.com/advisories/12048http://securitytracker.com/id?1010679http://www.kb.cert.org/vuls/id/413886http://www.osvdb.org/7774http://www.securityfocus.com/archive/1/368652http://www.securityfocus.com/archive/1/368666http://www.securityfocus.com/bid/10690http://www.us-cert.gov/cas/techalerts/TA04-293A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038https://exchange.xforce.ibmcloud.com/vulnerabilities/16675https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2611https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4363https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5620https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6031https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8077http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0498.htmlhttp://secunia.com/advisories/12048http://securitytracker.com/id?1010679http://www.kb.cert.org/vuls/id/413886http://www.osvdb.org/7774http://www.securityfocus.com/archive/1/368652http://www.securityfocus.com/archive/1/368666http://www.securityfocus.com/bid/10690http://www.us-cert.gov/cas/techalerts/TA04-293A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038https://exchange.xforce.ibmcloud.com/vulnerabilities/16675https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2611https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4363https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5620https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6031https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8077
2004-12-23
Published
Exploited in the wild