Vulnerability record · CVE-2006-1185 · published 11 April 2006
CVE-2006-1185: Microsoft Internet Explorer memory corruption via invalid HTML
Microsoft · Ie
CVE-2006-1185 is an unspecified memory corruption flaw in Microsoft Internet Explorer 5.01 through 6 that is triggered by certain invalid HTML. Successful exploitation allows remote code execution in the context of the browsing user. The record gives no root-cause detail beyond memory corruption, so the exact faulty component is unknown.
Description
Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a high CVSS 2.0 score of 7.5 and very high EPSS, though the affected software is legacy and no KEV listing or confirmed exploit is recorded.
What it is
CVE-2006-1185 is an unspecified memory corruption flaw in Microsoft Internet Explorer 5.01 through 6 that is triggered by certain invalid HTML. Successful exploitation allows remote code execution in the context of the browsing user. The record gives no root-cause detail beyond memory corruption, so the exact faulty component is unknown.
Impact
An attacker who gets the crafted HTML rendered can execute arbitrary code with the privileges of the IE user, giving full control of the affected workstation. No privilege escalation beyond the user's own rights is described.
Attack surface
Reachable over the network (AV:N) with no authentication (Au:N) and low attack complexity (AC:L), typically by a victim visiting or being directed to a malicious or compromised web page. User interaction in the form of browsing to the page is implied by the browser-based vector, though the record does not state it explicitly.
Exploitation
The record shows no CISA KEV listing and no reference tags indicating a public exploit, but EPSS is very high at 0.70001 (99.3rd percentile), suggesting elevated predicted exploitation activity. Actual in-the-wild exploitation is not documented in this data.
What to do
- Apply Microsoft security bulletin MS06-013, which addresses this issue, or upgrade to a supported IE version.
- Retire or isolate systems still running Internet Explorer 5.01 through 6, which are long out of support.
- Restrict browsing to trusted sites and block untrusted script/ActiveX content via browser and proxy policy.
- For the Canon Network Camera Server VB101, check the vendor for a fixed firmware or restrict its web interface to trusted networks.
Detection
- Monitor for IE crashes or unexpected process termination on hosts running legacy IE versions.
- Hunt for iexplore.exe spawning child processes such as cmd.exe, wscript.exe or powershell.exe.
- Review proxy and web logs for hosts contacting known malicious or newly registered domains serving HTML to legacy IE clients.
- Alert on unexpected outbound connections originating from workstations shortly after web browsing.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-1185 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-1185), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.