← Vulnerability feed

Vulnerability record · CVE-2005-2127 · published 19 August 2005

CVE-2005-2127: Internet Explorer COM Object Instantiation Memory Corruption

Ati · Catalyst Driver

Internet Explorer 5.01, 5.5, and 6 can be made to instantiate COM objects not intended for use in the browser via embedded CLSIDs in a web page. This causes memory corruption, leading to application crash and possibly arbitrary code execution, as demonstrated with Msdds.dll and dozens of other listed objects.

7.5 CVSS 2.0 High EPSS 64% · top 0.8% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
56References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 2.0 base score is 7.5 (HIGH) with network reachability and no authentication, and public exploit references exist, though the flaw affects only legacy Internet Explorer versions.

What it is

Internet Explorer 5.01, 5.5, and 6 can be made to instantiate COM objects not intended for use in the browser via embedded CLSIDs in a web page. This causes memory corruption, leading to application crash and possibly arbitrary code execution, as demonstrated with Msdds.dll and dozens of other listed objects.

Impact

An attacker can crash the browser and potentially execute arbitrary code in the context of the logged-on user. Successful code execution would give the attacker the user's privileges on the affected system.

Attack surface

Reached remotely over the network by luring a user to a malicious web page containing embedded CLSIDs; no authentication is required, but user interaction (visiting the page) is needed. The CVSS vector AV:N/AC:L/Au:N confirms network reachability with no authentication.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.63665, 99.18th percentile) and multiple references carry the Exploit tag, indicating public exploit material exists. No ransomware group is documented as using it.

What to do

  • Apply the Microsoft security update referenced in MS05-052 and the associated advisory 906267.
  • Disable or restrict the affected COM objects (for example Msdds.dll) from being instantiated in Internet Explorer via kill bits or the registry.
  • Upgrade to a supported browser that is not affected by this legacy COM instantiation issue.
  • Restrict browsing to trusted sites and block untrusted ActiveX/COM content through IE security zones.

Detection

  • Monitor for Internet Explorer processes loading the listed COM objects (Msdds.dll, Blnmgrps.dll, Ciodm.dll, Comsvcs.dll, and others) from unexpected paths.
  • Alert on IE crashes correlated with visits to untrusted or newly seen web pages.
  • Hunt for suspicious child processes spawned by iexplore.exe, which may indicate code execution following memory corruption.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://isc.sans.org/diary.php?date=2005-08-18 Third Party Advisory
http://secunia.com/advisories/16480 PatchVendor Advisory
http://secunia.com/advisories/17172 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/17223 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/17509 Permissions RequiredThird Party Advisory
http://securityreason.com/securityalert/72 Third Party Advisory
http://securitytracker.com/id?1014727 ExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf Third Party Advisory
http://www.kb.cert.org/vuls/id/740372 Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/898241 Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/959049 Third Party AdvisoryUS Government Resource
http://www.microsoft.com/technet/security/advisory/906267.mspx MitigationPatchVendor Advisory
http://www.securityfocus.com/archive/1/470690/100/0/threaded
http://www.securityfocus.com/bid/14594 ExploitPatchThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/15061 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA05-284A.html Third Party AdvisoryUS Government Resource
http://www.us-cert.gov/cas/techalerts/TA05-347A.html Third Party AdvisoryUS Government Resource
http://www.us-cert.gov/cas/techalerts/TA06-220A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2005/1450 Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-052
https://exchange.xforce.ibmcloud.com/vulnerabilities/21895 VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/34754 VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1155
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1454
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1464
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1468
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1535
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1538
http://isc.sans.org/diary.php?date=2005-08-18 Third Party Advisory
http://secunia.com/advisories/16480 PatchVendor Advisory
http://secunia.com/advisories/17172 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/17223 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/17509 Permissions RequiredThird Party Advisory
http://securityreason.com/securityalert/72 Third Party Advisory
http://securitytracker.com/id?1014727 ExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf Third Party Advisory
http://www.kb.cert.org/vuls/id/740372 Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/898241 Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/959049 Third Party AdvisoryUS Government Resource
http://www.microsoft.com/technet/security/advisory/906267.mspx MitigationPatchVendor Advisory

Track CVE-2005-2127 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed9.8CVE-2020-0646Microsoft .NET Framework input validation flaw enables remote code executionCVE-2020-0646 is a critical remote code execution vulnerability in the Microsoft .NET Framework caused by improper input validation, classified as XM…KEVEPSS 99%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed

Source: NIST National Vulnerability Database (record CVE-2005-2127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.