CVE-2006-4193

Microsoft Internet Explorer 6.0 SP1 - Remote Code Execution via COM Object Instantiation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-4193. PoCs published by nop.

AI-analyzed exploit summary This exploit leverages a vulnerability in Microsoft Internet Explorer by instantiating an ActiveX control (CLSID: {233A9694-667E-11d1-9DFB-006097D50408}) that fails to load the msoe.dll library, leading to a denial-of-service condition. The PoC is a simple HTML file that triggers the vulnerability when loaded in a vulnerable version of Internet Explorer.

Description

Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files.

Exploits (2)

exploitdb WORKING POC VERIFIED
by nop · htmldoswindows
https://www.exploit-db.com/exploits/28389

This exploit leverages a vulnerability in Microsoft Internet Explorer by instantiating an ActiveX control (CLSID: {233A9694-667E-11d1-9DFB-006097D50408}) that fails to load the msoe.dll library, leading to a denial-of-service condition. The PoC is a simple HTML file that triggers the vulnerability when loaded in a vulnerable version of Internet Explorer.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer (versions up to and including those on Windows 2000 SP4 and XP SP2)
No auth needed
Prerequisites: Victim must open the malicious HTML file in a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by nop · htmldoswindows
https://www.exploit-db.com/exploits/28387

This exploit leverages a vulnerability in Microsoft Internet Explorer by instantiating an ActiveX control with a specific CLSID, causing a denial-of-service (DoS) due to a failure in loading the IMSKDIC.DLL library. The PoC is a simple HTML file that triggers the vulnerability when loaded in a vulnerable version of Internet Explorer.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer (versions affected by CVE-2006-4193)
No auth needed
Prerequisites: Vulnerable version of Microsoft Internet Explorer · User interaction to load the malicious HTML file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (16)

Core 16
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28439
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29347
Exploit, Vendor Advisory x_refsource_misc
http://www.xsec.org/index.php?module=releases&act=view&type=1&id=8
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29345
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443295/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1402
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19530
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443290/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19521
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28436
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19529
Exploit, Vendor Advisory x_refsource_misc
http://www.xsec.org/index.php?module=releases&act=view&type=1&id=9
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29346
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443299/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28438

Scores

EPSS 0.4544
EPSS Percentile 98.6%

Details

Status published
Products (2)
microsoft/ie 6.0 sp1 (2 CPE variants)
microsoft/internet_explorer 6.0
Published Aug 17, 2006
Tracked Since Feb 18, 2026