CVE-2004-1043

EXPLOITED

Internet Explorer 6.0 on Windows XP SP2 - RCE

Title source: llm

Description

Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Paul · textremotewindows
https://www.exploit-db.com/exploits/719

Scores

EPSS 0.7450
EPSS Percentile 98.9%

Details

VulnCheck KEV 2005-01-11
Status published
Products (2)
microsoft/internet_explorer 6.0
microsoft/windows_xp
Published Dec 31, 2004
Tracked Since Feb 18, 2026