Vulnerability record · CVE-2006-4193 · published 17 August 2006
CVE-2006-4193: Internet Explorer COM Object Instantiation Memory Corruption
Microsoft · Ie
Internet Explorer 6.0 SP1 and possibly other versions allow remote attackers to instantiate COM objects as ActiveX controls, including imskdic.dll, chtskdic.dll and msoe.dll, leading to memory corruption. The record notes uncertainty whether the flaw lies in Internet Explorer itself or in the individual DLL files, and no affected version list beyond IE 6.0 SP1 is given.
Description
Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityCVSS 2.0 score is 7.5 (HIGH) with network reachability and no authentication, and EPSS is 0.47477 at the 98.8th percentile, though the record is old and lacks a confirmed patch reference.
What it is
Internet Explorer 6.0 SP1 and possibly other versions allow remote attackers to instantiate COM objects as ActiveX controls, including imskdic.dll, chtskdic.dll and msoe.dll, leading to memory corruption. The record notes uncertainty whether the flaw lies in Internet Explorer itself or in the individual DLL files, and no affected version list beyond IE 6.0 SP1 is given.
Impact
An attacker can cause a denial of service and possibly execute arbitrary code in the context of the affected process. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reached over the network via a crafted web page that instantiates the COM objects as ActiveX controls in Internet Explorer. The vector AV:N/AC:L/Au:N/C:P/I:P/A:P indicates no authentication is required; the record does not state whether user interaction is needed.
Exploitation
Not listed in CISA KEV, but multiple references are tagged Exploit and EPSS is 0.47477 (98.8th percentile), indicating a high likelihood of exploitation activity.
What to do
- Apply the Microsoft patch for the affected Internet Explorer and DLL components as soon as it is available.
- Disable or restrict ActiveX and COM object instantiation in Internet Explorer via security zones and kill bits.
- Upgrade from Internet Explorer 6.0 SP1 to a supported browser version.
- Block or filter untrusted web content that attempts to load the affected COM controls.
Detection
- Monitor for Internet Explorer processes loading imskdic.dll, chtskdic.dll or msoe.dll from unexpected paths.
- Alert on crashes or memory corruption events in iexplore.exe following ActiveX or COM object instantiation.
- Review proxy and web logs for pages hosting ActiveX controls that reference these DLLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-4193 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-4193), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.