CVE-2001-0643 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 11.4% (pctl 96)
Patch early
A public exploit exists.
Description
Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 11.36% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-09-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 5.5 - CLSID File Execution | 2001-04-17 |
References
- http://vil.nai.com/vil/virusSummary.asp?virus_k=99048
- http://www.guninski.com/clsidext.html
- http://www.osvdb.org/7858
- http://www.sarc.com/avcenter/venc/data/vbs.postcard%40mm.html
- http://www.securityfocus.com/archive/1/176909
- http://www.securityfocus.com/bid/2612
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6426
- http://vil.nai.com/vil/virusSummary.asp?virus_k=99048
- http://www.guninski.com/clsidext.html
- http://www.osvdb.org/7858
- http://www.sarc.com/avcenter/venc/data/vbs.postcard%40mm.html
- http://www.securityfocus.com/archive/1/176909
- http://www.securityfocus.com/bid/2612
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6426
→ the Explorer · watch your stack · NVD