← back
CVE-2006-2094

CVE-2006-2094

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 23%
from disclosure to weapon0 days
Published on NVDApr 29
1st PoCApr 26
exploitation probability
23%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.