CVE-2002-0371

Microsoft Internet Explorer 5.1-6.0 - Remote Code Execution via Gopher URL Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0371. PoCs published by [email protected].

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Microsoft Internet Explorer, Proxy Server, and ISA Server's gopher client. It includes shellcode designed to execute arbitrary code on vulnerable systems, specifically tested on Korean versions of Windows 2000 and Windows Me.

Description

Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.

Exploits (1)

exploitdb WORKING POC VERIFIED
by [email protected] · perlremotewindows
https://www.exploit-db.com/exploits/21510

This exploit targets a buffer overflow vulnerability in Microsoft Internet Explorer, Proxy Server, and ISA Server's gopher client. It includes shellcode designed to execute arbitrary code on vulnerable systems, specifically tested on Korean versions of Windows 2000 and Windows Me.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer, Proxy Server, and ISA Server (gopher client)
No auth needed
Prerequisites: Vulnerable version of Microsoft Internet Explorer, Proxy Server, or ISA Server · Ability to entice a user to connect to a malicious gopher server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4930
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9247.php
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102320516707940&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102397955217618&w=2
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A98
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/440275
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/276848
Various Sources x_refsource_misc
http://www.pivx.com/workaround_fail.html

Scores

EPSS 0.5444
EPSS Percentile 98.9%

Details

Status published
Products (6)
microsoft/internet_explorer 5.0.1 (3 CPE variants)
microsoft/internet_explorer 5.5 (3 CPE variants)
microsoft/internet_explorer 6.0
microsoft/isa_server 2000 (2 CPE variants)
microsoft/proxy_server 2.0 (2 CPE variants)
university_of_minnesota/gopher
Published Jul 03, 2002
Tracked Since Feb 18, 2026