Description
Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-015
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101103188711920&w=2
Scores
EPSS
0.1147
EPSS Percentile
95.6%
Details
Status
published
Products (3)
microsoft/internet_explorer
5.0.1 sp1 (2 CPE variants)
microsoft/internet_explorer
5.5 (3 CPE variants)
microsoft/internet_explorer
6.0
Published
Jan 13, 2002
Tracked Since
Feb 18, 2026