Back

CVE-2000-1061

Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious web page or email, aka the "Microsoft VM ActiveX Component" vulnerability.

Published: Dec 11, 2000 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft ie 4.x
microsoft ie 5.x

GitHub Security Advisory GHSA-7x8m-frjm-r4m8

Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 15.12%

Top 5% most likely to be exploited

Threat Score 24.9 / 100

Data Sources

NVD EPSS GitHub