Back

CVE-2001-0667

HIGH

Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.

Published: Oct 30, 2001 Modified: Jun 16, 2026
CWE-88 CWE-88

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: LOW Integrity Impact: LOW Availability Impact: LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products (1)

Vendor Product Version
microsoft internet_explorer *

GitHub Security Advisory GHSA-42w8-jq8g-mg7m

Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0,...

Risk Scores

CVSS Score 7.3 / 10
EPSS Score 14.68%

Top 4% most likely to be exploited

Threat Score 33.6 / 100

Data Sources

NVD EPSS GitHub