Vulnerability record · CVE-2006-1189 · published 11 April 2006
CVE-2006-1189: Internet Explorer URLMON.DLL buffer overflow via IDN DBCS URL parsing
Microsoft · Internet Explorer
URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 contains a buffer overflow triggered when parsing a crafted URL that uses an International Domain Name (IDN) with double-byte character sets (DBCS). Successful exploitation allows remote code execution in the context of the browsing user, making it a serious client-side flaw for any environment still running these IE versions.
Description
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and complete impact, plus a high EPSS percentile, though the affected IE versions are legacy.
What it is
URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 contains a buffer overflow triggered when parsing a crafted URL that uses an International Domain Name (IDN) with double-byte character sets (DBCS). Successful exploitation allows remote code execution in the context of the browsing user, making it a serious client-side flaw for any environment still running these IE versions.
Impact
An attacker can execute arbitrary code with the privileges of the user viewing the malicious URL, leading to full system compromise if that user has administrative rights. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached over the network via a crafted URL; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required. The description does not state whether user interaction beyond visiting or being redirected to the URL is needed, but it is a client-side browser parsing flaw.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded. EPSS is high (0.61386, 99.1st percentile), and references include vendor and US-CERT advisories, but no reference is tagged as public exploit code.
What to do
- Apply Microsoft security bulletin MS06-013, which addresses this vulnerability, or upgrade to a supported Internet Explorer version.
- Retire or isolate systems still running Internet Explorer 5.01 through 6, as these versions are long out of support.
- Enforce network-level controls (proxy filtering, egress restrictions) to limit browsing to trusted sites.
- Run browsing sessions with least privilege so code execution does not yield administrative rights.
Detection
- Monitor for IE crashes or abnormal process termination tied to URLMON.DLL.
- Inspect proxy and DNS logs for URLs containing IDN or DBCS-encoded hostnames from untrusted sources.
- Hunt for child processes spawned by iexplore.exe, which may indicate successful exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-1189 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-1189), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.