CVE-2006-0057
Status: ModifiedHigh (7.5)—
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 20%
- Percentile among all scored CVEs: 97
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- NVD-CWE-Other
References
- http://www.kb.cert.org/vuls/id/998297
- http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx
- http://www.osvdb.org/23657
- http://www.securityfocus.com/bid/16409
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24379
- http://www.kb.cert.org/vuls/id/998297
- http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx
- http://www.osvdb.org/23657
- http://www.securityfocus.com/bid/16409
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24379
Raw JSON (NVD)
Show
{
"id": "CVE-2006-0057",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-01-27T22:03:00.000",
"references": [
{
"url": "http://www.kb.cert.org/vuls/id/998297",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.osvdb.org/23657",
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/16409",
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24379",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/998297",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23657",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/16409",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24379",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054."
}
],
"lastModified": "2026-06-16T22:19:48.670",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B80088A3-2AA4-44A2-98DF-359E15F8E18B"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3F2A51E-2675-4993-B9C2-F2D176A92857"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D05ED9D0-CF78-4FAD-9371-6FB3D5825148"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D47247A3-7CD7-4D67-9D9B-A94A504DA1BE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}