cbcvebase.
CVE-2005-0053
published 2005-05-02

CVE-2005-0053: Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."

PriorityP269high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
63.49%
99.1th percentile
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftie
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftwindows_2003_server
microsoftwindows_2003_server
microsoftwindows_2003_server
microsoftwindows_2003_server
microsoftwindows_2003_server

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/24693.zip
  • Monitor for drag-and-drop operations from the Internet Zone that result in files being written to the local filesystem without a recognized extension, particularly files whose type is determined dynamically by the OS based on content rather than extension.
  • Alert on files dropped to the local filesystem from Internet Explorer that contain embedded HTML or script code but lack a file extension, as the OS content-sniffing mechanism may execute them.
  • Track drag-and-drop events in Internet Explorer 5.x/6 originating from the Internet Zone; MS04-038 did not fully block all permitted file types from being dropped onto the local computer.
  • ·The MS04-038 cumulative patch for Internet Explorer only partially mitigated the drag-and-drop attack surface; certain file types remained permitted and could still be abused.
  • ·Affected versions are Internet Explorer 5.01, 5.5, and 6; detection and mitigation efforts should be scoped to these versions.

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.