Exploitation Summary
CVE-2004-0839 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
References (14)
Core 14
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7721
Exploit, Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/10973
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109336221826652&w=2
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6272
Vendor Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/lists/fulldisclosure/2004/Aug/0868.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2073
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109303291513335&w=2
Patch, Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA04-293A.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4152
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3773
Patch, Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/526089
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17044
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1563
Scores
EPSS
0.3399
EPSS Percentile
98.2%
Details
VulnCheck KEV
2004-11-09
Status
published
Products (25)
avaya/definity_one_media_server
avaya/ip600_media_servers
avaya/modular_messaging_message_storage_server
1.1
avaya/modular_messaging_message_storage_server
2.0
avaya/s3400
avaya/s8100
microsoft/ie
6.0 sp1 (2 CPE variants)
microsoft/internet_explorer
5.0.1 (5 CPE variants)
microsoft/internet_explorer
5.5 (3 CPE variants)
microsoft/internet_explorer
6.0
... and 15 more
Published
Aug 18, 2004
Tracked Since
Feb 18, 2026