peter bassill · operator
$ cve CVE-2006-1186 JSON

CVE-2006-1186 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 57.9% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS57.93% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2006-04-11
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftie
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD