CVE-2003-0344

Microsoft Internet Explorer <6.0 - RCE

Title source: llm

Description

Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16581
exploitdb WORKING POC VERIFIED
by alumni · perlremotewindows
https://www.exploit-db.com/exploits/37
exploitdb WRITEUP VERIFIED
by FelineMenace · textremotewindows
https://www.exploit-db.com/exploits/22726
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms03_020_ie_objecttype.rb

Scores

EPSS 0.8649
EPSS Percentile 99.4%

Details

Status published
Products (4)
microsoft/ie 6.0
microsoft/internet_explorer 5.01
microsoft/internet_explorer 5.5
microsoft/internet_explorer 6.0
Published Jun 16, 2003
Tracked Since Feb 18, 2026