Vulnerability record · CVE-2006-1245 · published 17 March 2006
CVE-2006-1245: Microsoft Internet Explorer mshtml.dll buffer overflow via multiple event handlers
Microsoft · Ie
A buffer overflow exists in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180 (and probably other versions) when parsing an HTML tag containing a large number of script action handlers such as onload, onmouseover, or onclick. Successful exploitation allows remote code execution in the context of the browsing user, making a widely deployed browser component the attack target.
Description
Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows remote code execution with no authentication, has public exploit references, and a very high EPSS score, though the affected product is legacy and no KEV listing is present.
What it is
A buffer overflow exists in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180 (and probably other versions) when parsing an HTML tag containing a large number of script action handlers such as onload, onmouseover, or onclick. Successful exploitation allows remote code execution in the context of the browsing user, making a widely deployed browser component the attack target.
Impact
An attacker can execute arbitrary code with the privileges of the user running Internet Explorer, potentially leading to full system compromise. The CVSS 2.0 vector (AV:N/AC:L/Au:N/C:P/I:P/A:P) indicates partial confidentiality, integrity, and availability impact.
Attack surface
The flaw is reached remotely over the network by viewing a crafted HTML page or HTML email in Internet Explorer; no authentication is required, but user interaction (opening the page or message) is needed. The CVSS vector AV:N/AC:L/Au:N confirms network reachability with low complexity and no authentication.
Exploitation
The record is not listed in CISA KEV, but EPSS is 0.61821 (99.1st percentile) and multiple references carry an Exploit tag, indicating public exploit material exists. No ransomware group usage is documented.
What to do
- Apply the Microsoft security update MS06-013 (or later cumulative Internet Explorer update) to affected systems.
- Disable or restrict Active Scripting and event handler execution in Internet Explorer where feasible.
- Upgrade to a supported browser and operating system; Internet Explorer 6 is long out of support.
- Block or filter HTML email and web content that contains excessive script action handlers before it reaches the browser.
- Enforce network-level controls and email filtering to reduce exposure to crafted HTML pages.
Detection
- Monitor for crashes or abnormal process termination in iexplore.exe or mshtml.dll.
- Inspect web and email content for HTML tags with an unusually large number of event handler attributes (onload, onmouseover, onclick, etc.).
- Use endpoint detection to flag code execution originating from Internet Explorer processes, especially child processes or shell commands.
- Review proxy and IDS logs for known exploit URLs or patterns associated with this vulnerability.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-1245 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-1245), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.