cbcvebase.
CVE-2006-2766
published 2006-06-02

CVE-2006-2766: Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs…

PriorityP418low2.6CVSS 2.0
AVNACHAuNCNINAP
EXPLOIT
EPSS
47.92%
98.7th percentile
Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftie
microsoftinternet_explorer
microsoftinternet_explorer

Detection & IOCsextracted from sources · hover to see the quote

urlmhtml://mid:AAA...AAA (long mhtml URI in URL file)
filename.url
pathINETCOMM.DLL
  • Detect URL files (.url / Internet Shortcut) containing an oversized mhtml:// URI in the URL= field, particularly using the mhtml://mid: scheme prefix followed by a long string
  • Monitor for crashes or anomalous behaviour in INETCOMM.DLL loaded by iexplore.exe, explorer.exe, or outlook express (msimn.exe) when processing mhtml:// URIs
  • The PoC uses a crafted Internet Shortcut file with [InternetShortcut] section containing an oversized URL= value; inspect .url files delivered via email or web for abnormally long mhtml:// URL values
  • ·This is a user-assisted attack; exploitation requires the victim to open or interact with the malicious .url (Internet Shortcut) file
  • ·The published exploit is a PoC (Proof of Concept) causing a crash/DoS only; no code execution payload is demonstrated in the available source
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.