Vulnerability record · CVE-2005-0053 · published 2 May 2005
CVE-2005-0053: Internet Explorer drag-and-drop event handling allows remote code execution
Microsoft · Ie
Internet Explorer 5.01, 5.5, and 6 mishandle drag-and-drop events, allowing a remote attacker to execute arbitrary code. The flaw affects users on Windows 98, 98SE, ME, 2000, XP, and Server 2003, and Microsoft addressed it in security bulletins MS05-008 and MS05-014.
Description
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with a high EPSS score and public exploit references, though it affects only legacy, unsupported software.
What it is
Internet Explorer 5.01, 5.5, and 6 mishandle drag-and-drop events, allowing a remote attacker to execute arbitrary code. The flaw affects users on Windows 98, 98SE, ME, 2000, XP, and Server 2003, and Microsoft addressed it in security bulletins MS05-008 and MS05-014.
Impact
An attacker who successfully exploits the flaw can run arbitrary code with the privileges of the logged-on user, leading to full system compromise. Because the affected browser runs in the user's context, the attacker gains the user's access to files, credentials, and network resources.
Attack surface
The vulnerability is reached over the network through a crafted web page or HTML document that triggers drag-and-drop events in Internet Explorer. No authentication is required, but the victim must visit or open the malicious content and interact with the drag-and-drop element.
Exploitation
The record is not listed in CISA KEV, but EPSS is high at 0.59777 (99th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.
What to do
- Apply the Microsoft security updates referenced in MS05-008 and MS05-014, or the latest cumulative Internet Explorer update for the affected platform.
- Upgrade to a supported browser and operating system; Internet Explorer 5.x/6 and the listed Windows versions are long out of support.
- Disable or restrict drag-and-drop and active content in Internet Explorer through security zone settings where the browser must remain in use.
- Block or filter untrusted web content and restrict browsing to trusted sites to reduce exposure to malicious pages.
Detection
- Monitor for Internet Explorer processes spawning child processes such as cmd.exe, wscript.exe, or powershell.exe, which may indicate code execution from the browser.
- Review proxy and web logs for requests to known exploit-hosting domains or pages containing drag-and-drop event handlers.
- Use host-based detection to flag unexpected file creation or registry changes originating from iexplore.exe.
- Check for the presence of the MS05-008 and MS05-014 updates on affected systems to identify unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0053 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0053), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.