CVE-2006-4494 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 22.1% (pctl 98)
Patch early
A public exploit exists.
Description
Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 22.11% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-08-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | visual studio |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 6 - Visual Studio COM Object Instantiation Denial of Service | 2006-08-08 |
References
- http://securityreason.com/securityalert/1473
- http://www.securityfocus.com/archive/1/443499/100/100/threaded
- http://www.securityfocus.com/bid/19572
- http://www.xsec.org/index.php?module=releases&act=view&type=1&id=15
- http://securityreason.com/securityalert/1473
- http://www.securityfocus.com/archive/1/443499/100/100/threaded
- http://www.securityfocus.com/bid/19572
- http://www.xsec.org/index.php?module=releases&act=view&type=1&id=15
→ the Explorer · watch your stack · NVD