Vulnerability record · CVE-2004-0841 · published 23 December 2004
CVE-2004-0841: Internet Explorer 6.x arbitrary program installation via mousedown and drag-and-drop
Avaya · Ip600 Media Servers
Internet Explorer 6.x fails to properly restrict mousedown events that call the Popup.show method combined with drag-and-drop actions in a popup window, allowing a remote attacker to install arbitrary programs. This is a client-side code execution flaw in a widely deployed browser, so any user who visits a crafted page can be affected.
Description
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
AV:N/AC:L/Au:N/C:N/I:P/A:N
Automated analysis
high priorityAlthough the CVSS v2 score is medium (5.0), the flaw allows remote code installation with only user interaction, public exploit code is referenced, and EPSS is very high.
What it is
Internet Explorer 6.x fails to properly restrict mousedown events that call the Popup.show method combined with drag-and-drop actions in a popup window, allowing a remote attacker to install arbitrary programs. This is a client-side code execution flaw in a widely deployed browser, so any user who visits a crafted page can be affected.
Impact
An attacker can install and run arbitrary programs on the victim's machine, gaining the privileges of the logged-in user. This enables malware installation, data theft, or further compromise of the host.
Attack surface
Reached over the network via a malicious or compromised web page rendered in Internet Explorer 6.x; no authentication is required, but the victim must interact with the page (mousedown and drag-and-drop) for the exploit to trigger.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.487 probability, 98.8th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.
What to do
- Apply Microsoft security bulletin MS04-038 or the corresponding vendor patch for Internet Explorer 6.x.
- Upgrade to a supported, modern browser and remove or restrict Internet Explorer 6.x where it is still in use.
- Disable or restrict ActiveX and script-driven popup/drag-and-drop behavior via browser security zones and group policy.
- Block or filter untrusted web content at the network boundary and educate users not to interact with unexpected popups or drag-and-drop prompts.
- For affected Avaya products, apply the vendor's advisory guidance or isolate those systems from untrusted networks.
Detection
- Monitor for unexpected process creation or file writes originating from browser processes (iexplore.exe) on endpoints.
- Alert on network requests to known exploit or malicious content hosts referenced in threat intelligence.
- Review browser and proxy logs for visits to pages containing Popup.show or drag-and-drop abuse patterns.
- Use host-based detection for new executables or persistence mechanisms appearing shortly after browser activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0841 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0841), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.