CVE Database
/

CVE-2006-2094

Back to search

CVE-2006-2094

Published: Apr 29, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-1559
vdb-entry
x_refsource_VUPEN
17713
vdb-entry
x_refsource_BID
1015720
vdb-entry
x_refsource_SECTRACK
22351
vdb-entry
x_refsource_OSVDB
20040407 Race conditions in security dialogs
mailing-list
x_refsource_FULLDISC

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now