CVE-2007-0217
Microsoft Internet Explorer <6 - RCE
Title source: llmDescription
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Mathew Rowley · perldoswindows
https://www.exploit-db.com/exploits/3444
References (11)
Scores
EPSS
0.7577
EPSS Percentile
98.9%
Details
Status
published
Products (3)
microsoft/ie
6.0 sp1
microsoft/internet_explorer
5.01 sp4
microsoft/internet_explorer
6.0
Published
Feb 13, 2007
Tracked Since
Feb 18, 2026