CVE-2006-1186

Microsoft Internet Explorer <6 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1186.

AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2006-1186, which targets a vulnerability in Internet Explorer. The exploit uses malformed HTML tags to trigger a memory corruption issue, potentially leading to arbitrary code execution.

Description

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.

Exploits (1)

exploitdb WORKING POC
htmldoswindows
https://www.exploit-db.com/exploits/1838

This is a proof-of-concept exploit for CVE-2006-1186, which targets a vulnerability in Internet Explorer. The exploit uses malformed HTML tags to trigger a memory corruption issue, potentially leading to arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer
No auth needed
Prerequisites: Victim must visit a malicious webpage using a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (13)

Core 13
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/959049
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18957
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1589
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1446
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015900
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1651
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-101A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17453
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1318
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25545
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1704
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A791

Scores

EPSS 0.7482
EPSS Percentile 98.9%

Details

Status published
Products (7)
microsoft/ie 5.0.1 (4 CPE variants)
microsoft/ie 5.01 windows_2000_sp4
microsoft/ie 6 windows_server_2003_sp1
microsoft/internet_explorer 5.0.1 (5 CPE variants)
microsoft/internet_explorer 5.01 (5 CPE variants)
microsoft/internet_explorer 5.1
microsoft/internet_explorer 5.5 (4 CPE variants)
Published Apr 11, 2006
Tracked Since Feb 18, 2026