Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-2291Microsoft IE vulnerability

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
16.4%
top 5.13%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 31
Latest updateApr 29

Description

Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-vmrh-3f5r-7p82: Microsoft Windows Internet Explorer 52022-04-29
CVEList
CVE-2004-2291: Microsoft Windows Internet Explorer 52005-08-04

💥Exploits & PoCs

1
Exploit-DB
Microsoft Internet Explorer - Remote Application.Shell2004-07-09
CVE-2004-2291 — Microsoft IE vulnerability | cvebase