CVE-2003-0344
Microsoft Internet Explorer <6.0 - RCE
Title source: llmDescription
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16581
exploitdb
WRITEUP
VERIFIED
by FelineMenace · textremotewindows
https://www.exploit-db.com/exploits/22726
metasploit
WORKING POC
NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms03_020_ie_objecttype.rb
References (7)
Scores
EPSS
0.8649
EPSS Percentile
99.4%
Details
Status
published
Products (4)
microsoft/ie
6.0
microsoft/internet_explorer
5.01
microsoft/internet_explorer
5.5
microsoft/internet_explorer
6.0
Published
Jun 16, 2003
Tracked Since
Feb 18, 2026