CVE-2007-0217

Microsoft Internet Explorer <6 - RCE

Title source: llm

Description

The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mathew Rowley · perldoswindows
https://www.exploit-db.com/exploits/3444

Scores

EPSS 0.7577
EPSS Percentile 98.9%

Details

Status published
Products (3)
microsoft/ie 6.0 sp1
microsoft/internet_explorer 5.01 sp4
microsoft/internet_explorer 6.0
Published Feb 13, 2007
Tracked Since Feb 18, 2026