CVE-2005-2127

EXPLOITED

Microsoft Internet Explorer 5.01-6 - Remote Code Execution via Unsafe COM Object Instantiation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2005-2127 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including anonymous.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Microsoft Internet Explorer via the Msdds.dll COM object (CVE-2005-2127). It uses a JavaScript-based heap spray technique to execute a Win32 bind shell on port 28876.

Description

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · perlremotewindows
https://www.exploit-db.com/exploits/26167

This exploit targets a buffer overflow vulnerability in Microsoft Internet Explorer via the Msdds.dll COM object (CVE-2005-2127). It uses a JavaScript-based heap spray technique to execute a Win32 bind shell on port 28876.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer 6 SP2 (Windows XP SP2)
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (28)

Core 28
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/959049
Third Party Advisory x_refsource_misc
http://isc.sans.org/diary.php?date=2005-08-18
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/470690/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/72
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-347A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15061
Permissions Required, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17223
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1454
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16480
Mitigation, Patch, Vendor Advisory x_refsource_misc
http://www.microsoft.com/technet/security/advisory/906267.mspx
Permissions Required, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17172
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1538
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1535
Exploit, Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14594
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1468
Permissions Required, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17509
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-220A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1464
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/740372
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/898241
Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014727
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-284A.html
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1450
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1155

Scores

EPSS 0.4205
EPSS Percentile 97.5%

Details

VulnCheck KEV 2005-10-11
CWE
CWE-119
Status published
Products (15)
ati/catalyst_driver
microsoft/.net_framework 1.1 (4 CPE variants)
microsoft/office
microsoft/office 2000 (7 CPE variants)
microsoft/office xp sp1 (3 CPE variants)
microsoft/project 98
microsoft/project 2000
microsoft/project 2002 (2 CPE variants)
microsoft/project 2003 (2 CPE variants)
microsoft/visio 2000 sr1
... and 5 more
Published Aug 19, 2005
Tracked Since Feb 18, 2026