CVE-2005-3240

Microsoft IE - Race Condition

Title source: rule

Description

Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window.

Scores

EPSS 0.1023
EPSS Percentile 93.0%

Classification

CWE
CWE-362
Status draft

Affected Products (10)

microsoft/ie
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer

Timeline

Published Dec 31, 2005
Tracked Since Feb 18, 2026