Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2006-2766

Description

Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.

POC

Reference

- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-043

Github

- https://github.com/GuiMatosInfra/explorer2sectool

- https://github.com/xaitax/SploitScan