Vulnerability record · CVE-2006-1388 · published 24 March 2006
CVE-2006-1388: Microsoft Internet Explorer 6.0 HTA file execution flaw
Microsoft · Ie
CVE-2006-1388 is an unspecified vulnerability in Microsoft Internet Explorer 6.0 that allows remote attackers to execute HTA (HTML Application) files. The record does not describe the underlying mechanism, so the exact trigger is unknown, but successful exploitation gives code execution in the context of the browser. It matters because IE 6.0 was widely deployed and HTA execution bypasses normal browser security restrictions.
Description
Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe CVSS 2.0 base score is 7.5 (HIGH) with a network-reachable, no-authentication vector, and EPSS is at the 99th percentile, though the record lacks exploit confirmation and KEV listing.
What it is
CVE-2006-1388 is an unspecified vulnerability in Microsoft Internet Explorer 6.0 that allows remote attackers to execute HTA (HTML Application) files. The record does not describe the underlying mechanism, so the exact trigger is unknown, but successful exploitation gives code execution in the context of the browser. It matters because IE 6.0 was widely deployed and HTA execution bypasses normal browser security restrictions.
Impact
An attacker can cause Internet Explorer to execute an HTA file, which runs as a trusted application with the user's privileges rather than in the browser sandbox. This enables arbitrary code execution on the victim's system.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication required. The description does not state whether user interaction (such as visiting a crafted page) is needed, so that detail is missing from the record.
Exploitation
CVE-2006-1388 is not listed in CISA KEV and no ransomware use is documented. EPSS gives a 30-day exploitation probability of 0.55458 (99th percentile), indicating high predicted activity, but the references carry no exploit tags and no public exploit is confirmed in the record.
What to do
- Apply Microsoft security bulletin MS06-013, which addresses this issue.
- Upgrade from Internet Explorer 6.0 to a supported, current browser.
- Disable or restrict HTA file execution via application control or file association policy where operationally feasible.
- Block untrusted HTA and related active content at email and web gateways.
- Retire or isolate systems that cannot move off IE 6.0.
Detection
- Monitor for mshta.exe or HTA file execution spawned from browser processes such as iexplore.exe.
- Alert on HTA file downloads or execution originating from web or email content.
- Review proxy and DNS logs for known malicious or suspicious HTA delivery hosts.
- Audit endpoints still running Internet Explorer 6.0.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-1388 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-1388), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.