peter bassill · operator
$ cve CVE-2006-4494 JSON

CVE-2006-4494 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 22.1% (pctl 98)

Patch early

A public exploit exists.

Description

Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS22.11% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2006-08-31
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftvisual studio

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD