← Vulnerability feed

Vulnerability record · CVE-2004-0841 · published 23 December 2004

CVE-2004-0841: Internet Explorer 6.x arbitrary program installation via mousedown and drag-and-drop

Avaya · Ip600 Media Servers

Internet Explorer 6.x fails to properly restrict mousedown events that call the Popup.show method combined with drag-and-drop actions in a popup window, allowing a remote attacker to install arbitrary programs. This is a client-side code execution flaw in a widely deployed browser, so any user who visits a crafted page can be affected.

5.0 CVSS 2.0 Medium EPSS 49% · top 1.2%
5.0CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
34References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."

AV:N/AC:L/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityAlthough the CVSS v2 score is medium (5.0), the flaw allows remote code installation with only user interaction, public exploit code is referenced, and EPSS is very high.

What it is

Internet Explorer 6.x fails to properly restrict mousedown events that call the Popup.show method combined with drag-and-drop actions in a popup window, allowing a remote attacker to install arbitrary programs. This is a client-side code execution flaw in a widely deployed browser, so any user who visits a crafted page can be affected.

Impact

An attacker can install and run arbitrary programs on the victim's machine, gaining the privileges of the logged-in user. This enables malware installation, data theft, or further compromise of the host.

Attack surface

Reached over the network via a malicious or compromised web page rendered in Internet Explorer 6.x; no authentication is required, but the victim must interact with the page (mousedown and drag-and-drop) for the exploit to trigger.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.487 probability, 98.8th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.

What to do

  • Apply Microsoft security bulletin MS04-038 or the corresponding vendor patch for Internet Explorer 6.x.
  • Upgrade to a supported, modern browser and remove or restrict Internet Explorer 6.x where it is still in use.
  • Disable or restrict ActiveX and script-driven popup/drag-and-drop behavior via browser security zones and group policy.
  • Block or filter untrusted web content at the network boundary and educate users not to interact with unexpected popups or drag-and-drop prompts.
  • For affected Avaya products, apply the vendor's advisory guidance or isolate those systems from untrusted networks.

Detection

  • Monitor for unexpected process creation or file writes originating from browser processes (iexplore.exe) on endpoints.
  • Alert on network requests to known exploit or malicious content hosts referenced in threat intelligence.
  • Review browser and proxy logs for visits to pages containing Popup.show or drag-and-drop abuse patterns.
  • Use host-based detection for new executables or persistence mechanisms appearing shortly after browser activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0498.html
http://secunia.com/advisories/12048
http://securitytracker.com/id?1010679
http://www.kb.cert.org/vuls/id/413886 US Government Resource
http://www.osvdb.org/7774
http://www.securityfocus.com/archive/1/368652 ExploitPatchVendor Advisory
http://www.securityfocus.com/archive/1/368666
http://www.securityfocus.com/bid/10690 ExploitPatchVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-293A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
https://exchange.xforce.ibmcloud.com/vulnerabilities/16675
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2611
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4363
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5620
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6031
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6048
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8077
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0498.html
http://secunia.com/advisories/12048
http://securitytracker.com/id?1010679
http://www.kb.cert.org/vuls/id/413886 US Government Resource
http://www.osvdb.org/7774
http://www.securityfocus.com/archive/1/368652 ExploitPatchVendor Advisory
http://www.securityfocus.com/archive/1/368666
http://www.securityfocus.com/bid/10690 ExploitPatchVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-293A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
https://exchange.xforce.ibmcloud.com/vulnerabilities/16675
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2611
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4363
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5620
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6031
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6048
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8077

Track CVE-2004-0841 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1050Internet Explorer 6 heap overflow via IFRAME, FRAME and EMBED attributesInternet Explorer 6 contains a heap-based buffer overflow triggered by long SRC or NAME attributes in IFRAME, FRAME and EMBED elements. A remote atta…EPSS 67%analysed10.0CVE-2004-0201Microsoft HTML Help hh.exe heap buffer overflow via crafted CHM fileThe HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large len…EPSS 45%analysed10.0CVE-2004-0212Windows Task Scheduler .job file stack buffer overflowThe Windows Task Scheduler in Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, contains a stack-based buffer overflow triggered by a .…EPSS 64%analysed9.3CVE-2007-2374Microsoft windows 2000 vulnerabilityUnspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecif…EPSS 17%9.3CVE-2007-1765Microsoft Windows ANI cursor parsing memory corruptionMicrosoft Windows 2000 SP4 through Vista mishandles malformed ANI files when processing cursors, animated cursors and icons, causing memory corruptio…EPSS 55%analysed7.5CVE-2004-0842Internet Explorer CSS heap memory corruption denial of serviceInternet Explorer 6.0 SP1 and earlier mishandles malformed Cascading Style Sheet elements, triggering a heap-based buffer overflow that crashes the a…EPSS 57%analysed7.5CVE-2004-1307Avaya call management system server vulnerabilityInteger overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF …EPSS 6.3%7.5CVE-2004-1082Apache http server vulnerabilitymod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attacke…EPSS 7.6%

Source: NIST National Vulnerability Database (record CVE-2004-0841), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.