Vulnerability record · CVE-2005-2127 · published 19 August 2005
CVE-2005-2127: Internet Explorer COM Object Instantiation Memory Corruption
Ati · Catalyst Driver
Internet Explorer 5.01, 5.5, and 6 can be made to instantiate COM objects not intended for use in the browser via embedded CLSIDs in a web page. This causes memory corruption, leading to application crash and possibly arbitrary code execution, as demonstrated with Msdds.dll and dozens of other listed objects.
Description
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityCVSS 2.0 base score is 7.5 (HIGH) with network reachability and no authentication, and public exploit references exist, though the flaw affects only legacy Internet Explorer versions.
What it is
Internet Explorer 5.01, 5.5, and 6 can be made to instantiate COM objects not intended for use in the browser via embedded CLSIDs in a web page. This causes memory corruption, leading to application crash and possibly arbitrary code execution, as demonstrated with Msdds.dll and dozens of other listed objects.
Impact
An attacker can crash the browser and potentially execute arbitrary code in the context of the logged-on user. Successful code execution would give the attacker the user's privileges on the affected system.
Attack surface
Reached remotely over the network by luring a user to a malicious web page containing embedded CLSIDs; no authentication is required, but user interaction (visiting the page) is needed. The CVSS vector AV:N/AC:L/Au:N confirms network reachability with no authentication.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.63665, 99.18th percentile) and multiple references carry the Exploit tag, indicating public exploit material exists. No ransomware group is documented as using it.
What to do
- Apply the Microsoft security update referenced in MS05-052 and the associated advisory 906267.
- Disable or restrict the affected COM objects (for example Msdds.dll) from being instantiated in Internet Explorer via kill bits or the registry.
- Upgrade to a supported browser that is not affected by this legacy COM instantiation issue.
- Restrict browsing to trusted sites and block untrusted ActiveX/COM content through IE security zones.
Detection
- Monitor for Internet Explorer processes loading the listed COM objects (Msdds.dll, Blnmgrps.dll, Ciodm.dll, Comsvcs.dll, and others) from unexpected paths.
- Alert on IE crashes correlated with visits to untrusted or newly seen web pages.
- Hunt for suspicious child processes spawned by iexplore.exe, which may indicate code execution following memory corruption.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2127 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.