CVE-2006-4494
published 2006-08-31CVE-2006-4494: Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
21.58%
97.3th percentile
Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_studio | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor Internet Explorer processes for instantiation of the identified Visual Studio 6.0 COM/ActiveX objects (tcprops.dll, fp30wec.dll, mdt2db.dll, mdt2qd.dll, vi30aut.dll) as ActiveX controls, which is the trigger condition for this vulnerability. ↗
- →This issue affects a distinct set of COM objects not covered by prior mitigations for BID 14511 or BID 15061; ensure kill-bit enforcement is applied specifically to these five DLLs. ↗
- ·Remote code execution via this vulnerability has not been confirmed; the primary confirmed impact is memory corruption / denial of service. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://securityreason.com/securityalert/1473http://www.securityfocus.com/archive/1/443499/100/100/threadedhttp://www.securityfocus.com/bid/19572http://www.xsec.org/index.php?module=releases&act=view&type=1&id=15http://securityreason.com/securityalert/1473http://www.securityfocus.com/archive/1/443499/100/100/threadedhttp://www.securityfocus.com/bid/19572http://www.xsec.org/index.php?module=releases&act=view&type=1&id=15
2006-08-31
Published