CVE-2006-2094

Microsoft IE - Race Condition

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2094. PoCs published by Matthew Murphy.

AI-analyzed exploit summary This exploit leverages a race condition in Internet Explorer's modal security dialog boxes to trick users into allowing remote code execution via an ActiveX control installation. The PoC uses a fake CAPTCHA input to trigger the installation when the user presses 'N' or 'n'.

Description

Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Matthew Murphy · htmlremotewindows
https://www.exploit-db.com/exploits/27744

This exploit leverages a race condition in Internet Explorer's modal security dialog boxes to trick users into allowing remote code execution via an ActiveX control installation. The PoC uses a fake CAPTCHA input to trigger the installation when the user presses 'N' or 'n'.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target: Internet Explorer (versions affected by CVE-2006-2094)
No auth needed
Prerequisites: User interaction (pressing 'N' or 'n' in the CAPTCHA field) · ActiveX controls enabled in Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1559
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17713
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0759.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015720
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/22351
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045589.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26111
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0019.html
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0264.html

Scores

EPSS 0.2313
EPSS Percentile 97.5%

Details

CWE
CWE-362
Status published
Products (9)
microsoft/ie 5
microsoft/ie 5.0 (3 CPE variants)
microsoft/ie 5.0.1 (4 CPE variants)
microsoft/ie 6.0 sp1 (2 CPE variants)
microsoft/internet_explorer 5.0
microsoft/internet_explorer 5.0.1 (5 CPE variants)
microsoft/internet_explorer 5.5 (4 CPE variants)
microsoft/internet_explorer 6.0
microsoft/internet_explorer 7.0 beta1 (2 CPE variants)
Published Apr 29, 2006
Tracked Since Feb 18, 2026