peter bassill · operator
$ cve CVE-2001-0643 JSON

CVE-2001-0643 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 11.4% (pctl 96)

Patch early

A public exploit exists.

Description

Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS11.36% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2001-09-20
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

SourceTitleDate
exploit-dbMicrosoft Internet Explorer 5.5 - CLSID File Execution2001-04-17

References

→ the Explorer  ·  watch your stack  ·  NVD