CVE-2006-2094
Microsoft IE - Race Condition
Title source: ruleDescription
Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Matthew Murphy · htmlremotewindows
https://www.exploit-db.com/exploits/27744
References (11)
Scores
EPSS
0.3822
EPSS Percentile
97.2%
Details
CWE
CWE-362
Status
published
Products (9)
microsoft/ie
5
microsoft/ie
5.0 (3 CPE variants)
microsoft/ie
5.0.1 (4 CPE variants)
microsoft/ie
6.0 sp1 (2 CPE variants)
microsoft/internet_explorer
5.0
microsoft/internet_explorer
5.0.1 (5 CPE variants)
microsoft/internet_explorer
5.5 (4 CPE variants)
microsoft/internet_explorer
6.0
microsoft/internet_explorer
7.0 beta1 (2 CPE variants)
Published
Apr 29, 2006
Tracked Since
Feb 18, 2026