CVE-2005-0053
published 2005-05-02CVE-2005-0053: Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
PriorityP269high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
63.49%
99.1th percentile
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for drag-and-drop operations from the Internet Zone that result in files being written to the local filesystem without a recognized extension, particularly files whose type is determined dynamically by the OS based on content rather than extension. ↗
- →Alert on files dropped to the local filesystem from Internet Explorer that contain embedded HTML or script code but lack a file extension, as the OS content-sniffing mechanism may execute them. ↗
- →Track drag-and-drop events in Internet Explorer 5.x/6 originating from the Internet Zone; MS04-038 did not fully block all permitted file types from being dropped onto the local computer. ↗
- ·The MS04-038 cumulative patch for Internet Explorer only partially mitigated the drag-and-drop attack surface; certain file types remained permitted and could still be abused. ↗
- ·Affected versions are Internet Explorer 5.01, 5.5, and 6; detection and mitigation efforts should be scoped to these versions. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xj59-9vch-c6qw: Internet Explorer 5
ghsa_unreviewed·2022-05-01
CVE-2005-0053 [HIGH] GHSA-xj59-9vch-c6qw: Internet Explorer 5
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
VulnCheck
Microsoft Internet Explorer Drag-and-Drop Vulnerability
vulncheck·2005·CVSS 7.5
CVE-2005-0053 [HIGH] Microsoft Internet Explorer Drag-and-Drop Vulnerability
Microsoft Internet Explorer Drag-and-Drop Vulnerability
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
Affected: Microsoft Internet Explorer
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-008
No detection rules found.
No writeups or analysis indexed.
http://www.kb.cert.org/vuls/id/698835http://www.securityfocus.com/bid/11466http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-008https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-014https://exchange.xforce.ibmcloud.com/vulnerabilities/19117https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1015https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1334https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2046https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2953https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3006https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4726https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4864http://www.kb.cert.org/vuls/id/698835http://www.securityfocus.com/bid/11466http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-008https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-014https://exchange.xforce.ibmcloud.com/vulnerabilities/19117https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1015https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1334https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2046https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2953https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3006https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4726https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4864
2005-05-02
Published
Exploited in the wild