Vulnerability record · CVE-2003-0344 · published 16 June 2003
CVE-2003-0344: Internet Explorer Object tag Type property buffer overflow
Microsoft · Ie
Microsoft Internet Explorer 5.01, 5.5 and 6.0 contain a buffer overflow reachable through slash characters in the Type property of an Object tag in a web page. Successful exploitation allows remote code execution in the context of the browsing user, making it a serious client-side flaw for any environment still running these legacy IE versions.
Description
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution with no authentication required and very high EPSS, though the affected IE versions are long obsolete and no KEV listing or public exploit tag is present.
What it is
Microsoft Internet Explorer 5.01, 5.5 and 6.0 contain a buffer overflow reachable through slash characters in the Type property of an Object tag in a web page. Successful exploitation allows remote code execution in the context of the browsing user, making it a serious client-side flaw for any environment still running these legacy IE versions.
Impact
An attacker can execute arbitrary code on the victim's machine with the privileges of the logged-on user, enabling installation of malware, data theft or further lateral movement.
Attack surface
The flaw is reached over the network by viewing a crafted web page containing a malicious Object tag; no authentication is required, but the victim must browse to or be directed to the attacker-controlled page.
Exploitation
The record is not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.81307, 99.6th percentile), indicating strong likelihood of exploitation activity.
What to do
- Apply Microsoft security bulletin MS03-020 or the corresponding vendor patch immediately.
- Upgrade or retire Internet Explorer 5.01, 5.5 and 6.0 in favor of a supported browser.
- Restrict browsing to trusted sites and block untrusted ActiveX/Object content via IE security zones or policy.
- Where legacy IE cannot be removed, isolate affected hosts and limit user privileges to reduce post-exploitation impact.
Detection
- Monitor for IE processes spawning unexpected child processes such as cmd.exe or scripting hosts.
- Hunt proxy and web logs for pages containing Object tags with slash characters in the Type property.
- Review endpoint telemetry for crashes or abnormal memory behavior in iexplore.exe during browsing.
- Alert on outbound connections from browsing hosts to newly observed or low-reputation destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0344 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0344), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.