CVE-2006-1016

Internet Explorer 6.0 - Buffer Overflow via IsComponentInstalled Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-1016. PoCs published by Metasploit, hdm, including Metasploit module exploits/windows/browser/ie_iscomponentinstalled.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in Internet Explorer via the `isComponentInstalled` method, allowing remote code execution. It uses SEH overwrites and a randomized payload to bypass protections.

Description

Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16549

This Metasploit module exploits a stack buffer overflow in Internet Explorer via the `isComponentInstalled` method, allowing remote code execution. It uses SEH overwrites and a randomized payload to bypass protections.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Internet Explorer 6.0 on Windows XP SP0
No auth needed
Prerequisites: Target must be using Internet Explorer 6.0 on Windows XP SP0 · Target must visit a malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ie_iscomponentinstalled.rb

This Metasploit module exploits a stack buffer overflow in Internet Explorer via the `isComponentInstalled` method, allowing remote code execution. It uses SEH overwrites and a crafted HTML page to trigger the vulnerability.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer 6.0 on Windows XP SP0
No auth needed
Prerequisites: Victim must visit a malicious webpage · Target must be running vulnerable IE version
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16870
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24923

Scores

EPSS 0.6667
EPSS Percentile 99.2%

Details

Status published
Products (1)
microsoft/internet_explorer 6.0
Published Mar 07, 2006
Tracked Since Feb 18, 2026