Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious web page or email, aka the "Microsoft VM ActiveX Component" vulnerability.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/5127 | vdb entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-075 | vendor advisory |