CVE-2005-2127
published 2005-08-19CVE-2005-2127: Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a…
PriorityP270high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
63.67%
99.1th percentile
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | net_framework | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | project | — | — |
| microsoft | project | — | — |
| microsoft | project | — | — |
| microsoft | project | — | — |
| microsoft | visio | — | — |
| microsoft | visio | — | — |
| microsoft | visio | — | — |
| microsoft | visual_database_tools_database_designer | — | — |
| microsoft | visual_studio | — | — |
| microsoft | visual_studio_net | — | — |
| microsoft | visual_studio_net | — | — |
| microsoft | visual_studio_net | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
%u4343%u4343%u43eb
- →Detect instantiation of the vulnerable COM object CLSID EC444CB6-3E7E-4865-B1C3-0DE72EF39B3F (msdds.dll) via Internet Explorer — presence of this CLSID in HTML/script content is a strong indicator of exploitation attempts. ↗
- →Monitor for outbound or inbound TCP connections on port 28876, which is the bind-shell port opened by the exploit payload. ↗
- →Flag web pages containing both a JavaScript unescape() heap-spray block and an <object> or CLSID reference to EC444CB6-3E7E-4865-B1C3-0DE72EF39B3F as high-confidence CVE-2005-2127 exploit pages. ↗
- →This vulnerability is triggered via COM object instantiation in Internet Explorer; monitor iexplore.exe for loading of msdds.dll from unexpected or web-cache paths. ↗
- ·The exploit was tested specifically against Internet Explorer 6 SP2 on Windows XP SP2; detection rules targeting this CLSID may not apply to other browsers or OS versions. ↗
- ·The vulnerable msdds.dll may be installed by multiple applications beyond Visual Studio .NET; the affected package list should be treated as non-exhaustive. ↗
- ·CVE-2005-2127 (msdds.dll / EC444CB6 CLSID) is a distinct vulnerability from the related 'COM Object Instantiation Memory Corruption Vulnerability' CVE-2005-2831, though both involve COM object instantiation in IE. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hfcp-c62f-pjm6: Microsoft Internet Explorer 5
ghsa_unreviewed·2022-05-01
CVE-2005-2127 [HIGH] CWE-119 GHSA-hfcp-c62f-pjm6: Microsoft Internet Explorer 5
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole
GHSA
GHSA-8hx5-8mhr-hxfm: Stack-based buffer overflow in a certain ActiveX control in VDT70
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2007-4254 [HIGH] GHSA-8hx5-8mhr-hxfm: Stack-based buffer overflow in a certain ActiveX control in VDT70
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual Studio 6 allows remote attackers to execute arbitrary code via a long argument to the NotSafe method. NOTE: this may overlap CVE-2007-2885 or CVE-2005-2127.
GHSA
GHSA-h2vf-jw82-xqc6: Microsoft Internet Explorer 5
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2005-2831 [HIGH] GHSA-h2vf-jw82-xqc6: Microsoft Internet Explorer 5
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.
VulnCheck
ati catalyst_driver Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2005·CVSS 7.5
CVE-2005-2127 [HIGH] ati catalyst_driver Improper Restriction of Operations within the Bounds of a Memory Buffer
ati catalyst_driver Improper Restriction of Operations within the Bounds of a Memory Buffer
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Ms
No detection rules found.
http://isc.sans.org/diary.php?date=2005-08-18http://secunia.com/advisories/16480http://secunia.com/advisories/17172http://secunia.com/advisories/17223http://secunia.com/advisories/17509http://securityreason.com/securityalert/72http://securitytracker.com/id?1014727http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdfhttp://www.kb.cert.org/vuls/id/740372http://www.kb.cert.org/vuls/id/898241http://www.kb.cert.org/vuls/id/959049http://www.microsoft.com/technet/security/advisory/906267.mspxhttp://www.securityfocus.com/archive/1/470690/100/0/threadedhttp://www.securityfocus.com/bid/14594http://www.securityfocus.com/bid/15061http://www.us-cert.gov/cas/techalerts/TA05-284A.htmlhttp://www.us-cert.gov/cas/techalerts/TA05-347A.htmlhttp://www.us-cert.gov/cas/techalerts/TA06-220A.htmlhttp://www.vupen.com/english/advisories/2005/1450https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-052https://exchange.xforce.ibmcloud.com/vulnerabilities/21895https://exchange.xforce.ibmcloud.com/vulnerabilities/34754https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1155https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1454https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1464https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1468https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1535https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1538http://isc.sans.org/diary.php?date=2005-08-18http://secunia.com/advisories/16480http://secunia.com/advisories/17172http://secunia.com/advisories/17223http://secunia.com/advisories/17509http://securityreason.com/securityalert/72http://securitytracker.com/id?1014727http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdfhttp://www.kb.cert.org/vuls/id/740372http://www.kb.cert.org/vuls/id/898241http://www.kb.cert.org/vuls/id/959049http://www.microsoft.com/technet/security/advisory/906267.mspxhttp://www.securityfocus.com/archive/1/470690/100/0/threadedhttp://www.securityfocus.com/bid/14594http://www.securityfocus.com/bid/15061http://www.us-cert.gov/cas/techalerts/TA05-284A.htmlhttp://www.us-cert.gov/cas/techalerts/TA05-347A.htmlhttp://www.us-cert.gov/cas/techalerts/TA06-220A.htmlhttp://www.vupen.com/english/advisories/2005/1450https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-052https://exchange.xforce.ibmcloud.com/vulnerabilities/21895https://exchange.xforce.ibmcloud.com/vulnerabilities/34754https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1155https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1454https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1464https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1468https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1535https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1538
2005-08-19
Published
Exploited in the wild