Vulnerability record · CVE-2002-1217 · published 28 October 2002
CVE-2002-1217: Internet Explorer WebBrowser control cross-frame scripting code execution
Microsoft · Internet Explorer
The WebBrowser control in Internet Explorer 5.5 and 6.0 fails to enforce <frame> and <iframe> domain restrictions when script accesses the Document property. This cross-frame scripting flaw lets a remote attacker run script in a context that should be isolated, leading to arbitrary code execution or file reads. It matters because the affected browser was widely deployed and the flaw crosses a core security boundary.
Description
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityCVSS 2.0 base of 7.5 with network vector and no authentication, plus a public exploit reference and high EPSS, though the product is legacy and no KEV listing exists.
What it is
The WebBrowser control in Internet Explorer 5.5 and 6.0 fails to enforce <frame> and <iframe> domain restrictions when script accesses the Document property. This cross-frame scripting flaw lets a remote attacker run script in a context that should be isolated, leading to arbitrary code execution or file reads. It matters because the affected browser was widely deployed and the flaw crosses a core security boundary.
Impact
An attacker can execute arbitrary code in the victim's context, read arbitrary files, or perform other unauthorized actions on the affected system.
Attack surface
Reached over the network via a crafted web page or HTML document rendered by the vulnerable WebBrowser control; no authentication is required, but the victim must load the attacker's content (user interaction).
Exploitation
Not listed in CISA KEV, but a public exploit reference exists (greymagic advisory tagged Exploit), and EPSS is high at roughly 0.50 (98.8th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Microsoft security update MS02-066 for Internet Explorer 5.5 and 6.0.
- Upgrade to a supported, patched browser version; IE 5.5 and 6.0 are long end-of-life.
- Disable or restrict use of the WebBrowser control in embedded applications where it is not required.
- Enforce network controls and email/web filtering to block untrusted HTML reaching vulnerable hosts.
Detection
- Monitor for browser or WebBrowser control processes spawning unexpected child processes such as cmd.exe or scripting hosts.
- Review proxy and web logs for pages referencing cross-frame or Document-property script patterns tied to known exploit URLs.
- Alert on file access by browser processes to sensitive paths outside normal browsing behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-1217 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1217), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.