Vulnerability record · CVE-2005-0555 · published 12 April 2005
CVE-2005-0555: Microsoft Internet Explorer Content Advisor buffer overflow
Microsoft · Internet Explorer
A buffer overflow exists in the Content Advisor component of Microsoft Internet Explorer 5.01, 5.5, and 6. A remote attacker can trigger it with a crafted Content Advisor file, which can corrupt memory and potentially allow code execution in the context of the browser.
Description
Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows remote code execution with no authentication and has a very high EPSS score, though it is not listed in KEV and affects only legacy Internet Explorer versions.
What it is
A buffer overflow exists in the Content Advisor component of Microsoft Internet Explorer 5.01, 5.5, and 6. A remote attacker can trigger it with a crafted Content Advisor file, which can corrupt memory and potentially allow code execution in the context of the browser.
Impact
Successful exploitation can let an attacker execute arbitrary code with the privileges of the user running Internet Explorer. That could lead to full compromise of the affected system or user session.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no authentication required (AC:L/Au:N). It is triggered by a crafted Content Advisor file, so some form of user interaction or file delivery is likely needed, though the record does not specify the exact delivery mechanism.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit tags, so confirmed in-the-wild exploitation is not established. EPSS is high at 0.58357 (99th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Apply the Microsoft security update referenced in MS05-020 as the primary fix.
- Upgrade or retire Internet Explorer 5.01, 5.5, and 6 where still in use.
- Restrict or disable Content Advisor functionality if it is not required.
- Block untrusted Content Advisor files and enforce attachment/file handling controls at email and web gateways.
- Limit user privileges so browser compromise does not immediately yield administrative access.
Detection
- Monitor for Internet Explorer crashes or memory corruption events tied to Content Advisor processing.
- Hunt for suspicious Content Advisor file creation or execution on endpoints.
- Review proxy, email, and web gateway logs for delivery of Content Advisor files from untrusted sources.
- Use the available OVAL definitions to check for missing MS05-020 patches on affected systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0555 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0555), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.