CVE-2006-4495

Microsoft Internet Explorer - Remote Code Execution via ActiveX COM Object Instantiation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-4495. PoCs published by nop.

AI-analyzed exploit summary This exploit tests multiple COM objects in Internet Explorer on Windows 2000, attempting to instantiate them as ActiveX controls. The goal is to trigger memory corruption vulnerabilities that could lead to arbitrary code execution.

Description

Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.

Exploits (1)

exploitdb WORKING POC VERIFIED
by nop · htmldoswindows
https://www.exploit-db.com/exploits/28420

This exploit tests multiple COM objects in Internet Explorer on Windows 2000, attempting to instantiate them as ActiveX controls. The goal is to trigger memory corruption vulnerabilities that could lead to arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft Windows 2000 SP4 (Internet Explorer)
No auth needed
Prerequisites: Victim must be using Windows 2000 with Internet Explorer · JavaScript must be enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1474
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19636
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443896/100/100/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28512

Scores

EPSS 0.2021
EPSS Percentile 97.1%

Details

Status published
Products (5)
microsoft/ie 6.0 sp1
microsoft/windows_2003_server 2000_server (5 CPE variants)
microsoft/windows_2003_server advanced_server (5 CPE variants)
microsoft/windows_2003_server datacenter_server (5 CPE variants)
microsoft/windows_2003_server professional (5 CPE variants)
Published Aug 31, 2006
Tracked Since Feb 18, 2026