cbcvebase.
CVE-2005-0553
published 2005-05-02

CVE-2005-0553: Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to…

PriorityP336medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EXPLOIT
EPSS
50.60%
98.8th percentile
Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftie
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/25386.zip
  • Exploit targets DHTML object processing in Internet Explorer 5.01, 5.5, and 6 via a malicious web page or HTML e-mail; monitor for IE processes spawning unexpected child processes or shellcode execution following DHTML/script object rendering.
  • Trigger condition involves processing of certain script objects in DHTML; inspect HTML e-mail and web content for malformed or race-condition-inducing DHTML script object patterns.
  • ·Affected versions are limited to Internet Explorer 5.01, 5.5, and 6; detection efforts should be scoped to these legacy versions only.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.