Vulnerability record · CVE-2006-1190 · published 11 April 2006
CVE-2006-1190: Internet Explorer embedded object zone confusion allows code execution
Microsoft · Internet Explorer
Internet Explorer 5.01 through 6 fails to return correct IOleClientSite information when dynamically creating an embedded object, so the object can be run in the wrong security context or zone. This zone/context confusion lets a remote attacker escape the intended restrictions and execute arbitrary code in the user's browser session.
Description
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and full confidentiality, integrity and availability impact, plus a very high EPSS percentile, makes this a top-priority exposure wherever affected IE versions remain.
What it is
Internet Explorer 5.01 through 6 fails to return correct IOleClientSite information when dynamically creating an embedded object, so the object can be run in the wrong security context or zone. This zone/context confusion lets a remote attacker escape the intended restrictions and execute arbitrary code in the user's browser session.
Impact
An attacker can execute arbitrary code with the privileges of the logged-on user, giving full control of confidentiality, integrity and availability on the affected host. In practice this means code execution in the browser's security context rather than the restricted zone the content should have been confined to.
Attack surface
Reached over the network via a crafted web page or embedded object that triggers dynamic object creation in Internet Explorer; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction beyond loading the content. The record does not describe the exact delivery mechanism in more detail.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is 0.61293 (99.1st percentile), indicating a high modeled likelihood of exploitation activity. The record does not confirm public exploit availability.
What to do
- Apply Microsoft security bulletin MS06-013, which addresses this issue, or upgrade off the affected Internet Explorer 5.01-6 releases.
- Restrict browsing to trusted sites and disable or block ActiveX and embedded object rendering where business use allows.
- Run Internet Explorer with reduced privileges and enforce zone hardening so untrusted content cannot reach privileged object creation paths.
- Retire or isolate end-of-life Internet Explorer versions that cannot be patched.
Detection
- Monitor for Internet Explorer processes spawning child processes or writing executables shortly after browsing untrusted content.
- Alert on crashes or anomalous object instantiation in iexplore.exe, particularly around embedded object creation.
- Review proxy and web logs for known malicious or untrusted sites visited by hosts still running IE 5.01-6.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-1190 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-1190), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.