Vulnerability record · CVE-2006-3730 · published 21 July 2006
CVE-2006-3730: Internet Explorer 6 WebViewFolderIcon ActiveX setSlice integer overflow
Microsoft · Ie
An integer overflow in the setSlice method of the WebViewFolderIcon ActiveX control in Microsoft Internet Explorer 6 on Windows XP SP2 allows a remote attacker to corrupt memory via a crafted 0x7fffffff argument. The flaw leads to an invalid memory copy that can crash the browser and, under the right conditions, allow arbitrary code execution. It matters because IE 6 was widely deployed and the control is reachable from ordinary web content.
Description
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability, public exploit code, and a very high EPSS score, though exploitation is limited to legacy IE 6 on Windows XP SP2.
What it is
An integer overflow in the setSlice method of the WebViewFolderIcon ActiveX control in Microsoft Internet Explorer 6 on Windows XP SP2 allows a remote attacker to corrupt memory via a crafted 0x7fffffff argument. The flaw leads to an invalid memory copy that can crash the browser and, under the right conditions, allow arbitrary code execution. It matters because IE 6 was widely deployed and the control is reachable from ordinary web content.
Impact
An attacker can crash the browser and potentially execute arbitrary code in the context of the logged-on user. Successful exploitation gives the attacker the same privileges as the victim, enabling further compromise of the host.
Attack surface
Reached remotely over the network by a victim visiting a malicious or compromised web page that instantiates the WebViewFolderIcon ActiveX object and calls setSlice. No authentication is required, but user interaction (loading the page) is needed per the CVSS vector.
Exploitation
Public exploit references exist, including Exploit-DB entry 2440 and multiple Exploit-tagged links, and EPSS is high at 0.638 (99th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded in that source.
What to do
- Apply Microsoft security bulletin MS06-057, which addresses this vulnerability.
- Disable or kill-bit the WebViewFolderIcon ActiveX control where it is not required.
- Restrict ActiveX execution in Internet Explorer via zone and ActiveX security settings.
- Upgrade from Internet Explorer 6 to a supported browser version.
- Block or filter untrusted web content that instantiates legacy ActiveX controls.
Detection
- Monitor for browser crashes or abnormal process termination in iexplore.exe on legacy Windows XP systems.
- Detect network requests to pages or hosts known to deliver setSlice exploit code.
- Audit ActiveX control instantiation and kill-bit registry settings for WebViewFolderIcon.
- Review endpoint logs for suspicious child processes spawned by iexplore.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-3730 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-3730), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.