Description
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/7823
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5567
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/2456
Various Sources x_refsource_misc
http://www.guninski.com/chmtempmain.html
Scores
EPSS
0.2021
EPSS Percentile
97.2%
Details
Status
published
Products (4)
microsoft/internet_explorer
5.01
microsoft/internet_explorer
< 5.5
microsoft/windows_script_host
5.1
microsoft/windows_script_host
5.5
Published
Jul 21, 2001
Tracked Since
Feb 18, 2026