CVE-2006-4495
Microsoft Internet Explorer - Remote Code Execution via ActiveX COM Object Instantiation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4495. PoCs published by nop.
AI-analyzed exploit summary This exploit tests multiple COM objects in Internet Explorer on Windows 2000, attempting to instantiate them as ActiveX controls. The goal is to trigger memory corruption vulnerabilities that could lead to arbitrary code execution.
Description
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
Exploits (1)
This exploit tests multiple COM objects in Internet Explorer on Windows 2000, attempting to instantiate them as ActiveX controls. The goal is to trigger memory corruption vulnerabilities that could lead to arbitrary code execution.