Vulnerability record · CVE-2004-1050 · published 31 December 2004
CVE-2004-1050: Internet Explorer 6 heap overflow via IFRAME, FRAME and EMBED attributes
Avaya · Ip600 Media Servers
Internet Explorer 6 contains a heap-based buffer overflow triggered by long SRC or NAME attributes in IFRAME, FRAME and EMBED elements. A remote attacker can craft a malicious HTML page that corrupts heap memory and executes arbitrary code in the context of the browsing user. The flaw was originally found with the mangleme fuzzing utility and is known as the IFRAME or HTML Elements vulnerability.
Description
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score is 10.0 with complete confidentiality, integrity and availability impact, and EPSS is above the 99th percentile, so the flaw is both severe and highly likely to be exploited.
What it is
Internet Explorer 6 contains a heap-based buffer overflow triggered by long SRC or NAME attributes in IFRAME, FRAME and EMBED elements. A remote attacker can craft a malicious HTML page that corrupts heap memory and executes arbitrary code in the context of the browsing user. The flaw was originally found with the mangleme fuzzing utility and is known as the IFRAME or HTML Elements vulnerability.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the user running Internet Explorer. This can lead to full system compromise, data theft or installation of malware.
Attack surface
The attack is network-reachable (AV:N) with no authentication required (Au:N) and low complexity (AC:L). It is delivered through a web page or HTML content that the victim must load in Internet Explorer, so user interaction in the form of visiting or rendering the page is required.
Exploitation
The record is not listed in CISA KEV and no ransomware groups are documented as using it. EPSS is high (0.67061, 99.264th percentile), and the references include public advisories and a Microsoft security bulletin, indicating public technical detail is available, but the record does not state whether a working exploit is publicly available.
What to do
- Apply Microsoft security bulletin MS04-040 or the corresponding vendor patch for Internet Explorer 6.
- Upgrade to a supported, modern browser and remove or isolate Internet Explorer 6 from production use.
- Disable or restrict ActiveX and other legacy IE rendering features where possible.
- Block or filter HTML content with oversized SRC or NAME attributes in IFRAME, FRAME and EMBED elements at email and web gateways.
- Apply the Avaya patches for the listed media server and messaging products that bundle the affected IE component.
Detection
- Monitor web proxy and email gateway logs for HTML containing unusually long SRC or NAME attributes in IFRAME, FRAME or EMBED tags.
- Hunt for iexplore.exe crashes or abnormal child processes spawned from Internet Explorer on endpoints.
- Use network IDS signatures for the known IFRAME/HTML element overflow patterns if available.
- Review endpoint telemetry for code execution or file writes originating from iexplore.exe rendering untrusted web content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-1050 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1050), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.