CVE-2001-0149

Windows Scripting Host - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0149. PoCs published by Georgi Guninski.

AI-analyzed exploit summary This exploit leverages a vulnerability in Microsoft Internet Explorer and Outlook Express via the 'GetObject()' JScript function and the 'htmlfile' ActiveX object to read arbitrary files on the victim's system. The PoC includes a Base64-encoded payload to bypass patches, demonstrating an information leak attack.

Description

Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Georgi Guninski · htmlremotewindows
https://www.exploit-db.com/exploits/20243

This exploit leverages a vulnerability in Microsoft Internet Explorer and Outlook Express via the 'GetObject()' JScript function and the 'htmlfile' ActiveX object to read arbitrary files on the victim's system. The PoC includes a Base64-encoded payload to bypass patches, demonstrating an information leak attack.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer, Outlook Express (Windows Script Host)
No auth needed
Prerequisites: Victim must open a malicious HTML document or email · Known file path on the victim's system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=96999020527583&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1718
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-09/0305.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5293

Scores

EPSS 0.3221
EPSS Percentile 98.1%

Details

Status published
Products (1)
microsoft/internet_explorer < 5.5
Published Jun 02, 2001
Tracked Since Feb 18, 2026