CVE-2006-2094

Microsoft IE - Race Condition

Title source: rule

Description

Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Matthew Murphy · htmlremotewindows
https://www.exploit-db.com/exploits/27744

Scores

EPSS 0.3822
EPSS Percentile 97.2%

Details

CWE
CWE-362
Status published
Products (9)
microsoft/ie 5
microsoft/ie 5.0 (3 CPE variants)
microsoft/ie 5.0.1 (4 CPE variants)
microsoft/ie 6.0 sp1 (2 CPE variants)
microsoft/internet_explorer 5.0
microsoft/internet_explorer 5.0.1 (5 CPE variants)
microsoft/internet_explorer 5.5 (4 CPE variants)
microsoft/internet_explorer 6.0
microsoft/internet_explorer 7.0 beta1 (2 CPE variants)
Published Apr 29, 2006
Tracked Since Feb 18, 2026