Vulnerability record · CVE-2005-2087 · published 5 July 2005
CVE-2005-2087: Internet Explorer COM CLSID handling crash and possible code execution
Microsoft · Ie
Internet Explorer 5.01 SP4 through 6 on various Windows versions mishandles web pages that embed CLSIDs referencing COM objects that are not ActiveX controls, as demonstrated with the JVIEW Profiler (Javaprxy.dll). A remote page can crash the browser and possibly execute arbitrary code. The researcher notes the vendor could not reproduce the problem, so the flaw's real-world behavior is uncertain.
Description
Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll). NOTE: the researcher says that the vendor could not reproduce this problem.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated crash with possible code execution, but the vendor could not reproduce it, no KEV listing, and the affected IE versions are obsolete.
What it is
Internet Explorer 5.01 SP4 through 6 on various Windows versions mishandles web pages that embed CLSIDs referencing COM objects that are not ActiveX controls, as demonstrated with the JVIEW Profiler (Javaprxy.dll). A remote page can crash the browser and possibly execute arbitrary code. The researcher notes the vendor could not reproduce the problem, so the flaw's real-world behavior is uncertain.
Impact
An attacker can crash the victim's browser, causing a denial of service, and potentially execute arbitrary code in the context of the IE process. The code execution outcome is described as possible, not confirmed.
Attack surface
Reached over the network by luring a user to a malicious or compromised web page; no authentication is required, but user interaction (visiting the page) is needed. The CVSS vector AV:N/AC:L/Au:N confirms remote, low-complexity, unauthenticated access.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS is high (0.61, 99th percentile), but references are advisories and government alerts with no public exploit tag, and the vendor reportedly could not reproduce the issue.
What to do
- Apply the Microsoft security update referenced in MS05-037 and the associated advisory 903144, or upgrade to a supported IE/Windows version since IE 5.01-6 are long out of support.
- Disable or unregister the JVIEW Profiler (Javaprxy.dll) and other non-ActiveX COM objects reachable from IE where feasible.
- Restrict browsing to trusted sites and block untrusted ActiveX/COM object instantiation via IE security zones and kill-bit settings.
- Enforce least privilege so a successful code execution cannot escalate to administrative rights.
Detection
- Monitor for iexplore.exe crashes and unexpected child process creation from IE, especially involving javaprxy.dll or other COM object loads.
- Alert on network requests to pages embedding CLSID references to non-ActiveX COM objects, using proxy or IDS signatures where available.
- Review endpoint logs for suspicious module loads into iexplore.exe and correlate with user web browsing activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2087 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2087), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.