Denial of Service Vulnerability in Microsoft Internet Explorer's System Information ActiveX Control
CVE-2006-4627
Currently unrated
What is CVE-2006-4627?
The System Information ActiveX control (msinfo.dll) in Microsoft Internet Explorer is susceptible to a vulnerability that allows remote attackers to exploit the SaveFile function. By sending specially crafted input with excessive lengths for the computer name, filename, or category arguments, an attacker can trigger a crash, resulting in a denial of service. This vulnerability highlights the need for robust security measures in ActiveX components to prevent unauthorized access and potential disruptions.