cbcvebase.
CVE-2006-3637
published 2006-08-08

CVE-2006-3637: Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to…

PriorityP432medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EXPLOIT
EPSS
43.76%
98.6th percentile
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftie
microsoftinternet_explorer<= 6.0
microsoftinternet_explorer

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/27971.zip
  • Exploit targets Internet Explorer frameset handling — monitor for HTML pages containing frameset elements with a single frame invoking resizeTo() with unusual arguments, which may indicate exploitation attempts.
  • Exploitation requires user interaction (clicking anywhere on the page after visiting a malicious site) — social engineering lure pages targeting IE 5.x/6.x users should be flagged.
  • The vulnerability can lead to arbitrary code execution in the context of the victim user, not just denial of service — treat crashes in iexplore.exe following frameset rendering as potentially exploitable.
  • ·The CVE relationship between CVE-2006-3637 and CVE-2006-7029 is uncertain — the NVD notes these issues 'might be related', so detections built for one may or may not cover the other.
  • ·Affected scope spans Internet Explorer 5.0.1 through 6 SP2 and earlier — detections should account for both version lines.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.