Description
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
References (1)
Core 1
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-15&msg=20000221103938.T21312%40securityfocus.com
Scores
EPSS
0.0921
EPSS Percentile
94.8%
Details
Status
published
Products (3)
microsoft/ie
4.x
microsoft/internet_explorer
5
microsoft/outlook
Published
Feb 21, 2000
Tracked Since
Feb 18, 2026