CVE-2006-0005
published 2006-02-14CVE-2006-0005: Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default…
PriorityP268critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
39.17%
98.4th percentile
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows-nt | — | — |
| microsoft | windows-nt | — | — |
| microsoft | windows-nt | — | — |
| microsoft | windows_2000_advanced_server | — | — |
| microsoft | windows_2000_advanced_server | — | — |
| microsoft | windows_2000_advanced_server | — | — |
| microsoft | windows_2000_advanced_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_server_2000 | — | — |
| microsoft | windows_server_2000 | — | — |
| microsoft | windows_server_2000 | — | — |
| microsoft | windows_server_2000 | — | — |
| microsoft | windows_server_2003 | — | — |
| microsoft | windows_server_2003 | — | — |
| microsoft | windows_server_2003 | — | — |
| microsoft | windows_server_2003 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
%u4141%u4141%u4141%u4141%u4141%u4141%u4141%u4141 (heap spray NOP sled pattern)
bytes↗
AAAABBBBCCCCDDDDEEEEFFFFGGGGHHHHIIIIJJJJKKKKLLLL...AAA\x05...AAA\x05...QQQQRRRRSSSSTTTTUUUUVVVVWWWWXXXXYYYYZZZZ0000111122223333444455556666777788889999.wmv (overflow pattern with SEH overwrite)
bytes↗
GetPC stub: \x58\x58\x58\x05\x18\x29\x29\x29\x2d\x01\x29\x29\x29\x50\x59
bytes↗
SEH frame overwrite at offset 2086 in overflow buffer
- →Detect HTML pages containing an EMBED element with an excessively long SRC attribute (>2000 characters), characteristic of the WMP plugin overflow exploit. ↗
- →Detect heap spray pattern using repeated %u4141 Unicode escape sequences in JavaScript unescape() calls within HTML pages served to Firefox/Opera on Windows. ↗
- →Detect HTTP responses with Content-Type text/html serving EMBED tags with .wmv SRC values exceeding 2000 bytes, targeting the WMP plugin overflow at offset ~2082-2090. ↗
- →Characters with the sign bit set (>0x7F) are stripped from the overflow buffer; payloads will be restricted to 7-bit ASCII (BadChars: 0x80-0xFF), aiding in distinguishing exploit traffic. ↗
- ·The vulnerability only affects the WMP plugin when used in non-Microsoft browsers (Firefox, Opera, etc.) set as the default handler for media files; Internet Explorer is not affected. ↗
- ·The Metasploit module does not detect Windows SP level or WMP version from the User-Agent alone; target address selection may be inaccurate, affecting reliability of detection signatures based on specific return addresses. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6h2j-xchg-wcx8: Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the de
ghsa_unreviewed·2022-05-01
CVE-2006-0005 [HIGH] CWE-119 GHSA-6h2j-xchg-wcx8: Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the de
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
VulnCheck
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2006·CVSS 9.3
CVE-2006-0005 [CRITICAL] Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.virusbulletin.com/virusbulletin/2010/05/exploit-kit-explosion-part-two-vectors-attack/
No detection rules found.
Exploit-DB
Man Command - -H Flag Local Buffer Overflow
exploitdb·2007-04-06·CVSS 6.9
CVE-2006-4250 [MEDIUM] Man Command - -H Flag Local Buffer Overflow
Man Command - -H Flag Local Buffer Overflow
---
// source: https://www.securityfocus.com/bid/23355/info
The 'man' command is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.
NOTE: Presumably, this issue is exploitable only when 'man' has been installed setuid.
Exploiting this issue allows attackers to execute malicious machine code with the privileges of the 'man' utility. This can result in the compromise of affected computers. Failed exploit attempts will likely result in denial-of-service conditions.
PoC Code:
/*
* Linux Omnikey Cardman 4040 driver buffer overflow (CVE-2007-0005)
* Copyright (C) Daniel Roethlisberger
* Compass Security Network Computing AG, Rapperswil, Switzerla
Exploit-DB
Microsoft Windows Media Player - Plugin Overflow (MS06-006) (3)
exploitdb·2006-02-22
CVE-2006-0005 Microsoft Windows Media Player - Plugin Overflow (MS06-006) (3)
Microsoft Windows Media Player - Plugin Overflow (MS06-006) (3)
---
#!/usr/bin/perl
#
# wmp-profiteer.pl
# Exploiting 'Non-Critical' Media Player Vulnerabilities for Fun and Profit
# By Matthew Murphy ([email protected])
#
# It's come to my attention that the HTML versions of the exploit posted on
# several sites have become mangled. Notables include SecuriTeam and FrSIRT.
# Neither one, though, can beat SecurityFocus, whose links to the exploits
# for this issue are both 404s.
#
# I haven't updated the underlying exploit methodology -- it's still a shameless
# rip of Skylined's heap spray technique, but now the shellcode can be
# customized!
#
# The usage of this tool is as follows:
#
# wmp-profiteer.pl [shellcode]
#
# The shellcode that comes with this has the same payload as the or
Exploit-DB
Microsoft Windows Media Player 10 - Plugin Overflow (MS06-006)
exploitdb·2006-02-17
CVE-2006-0005 Microsoft Windows Media Player 10 - Plugin Overflow (MS06-006)
Microsoft Windows Media Player 10 - Plugin Overflow (MS06-006)
---
WMP Plugin EMBED Exploit
// Windows Media Player Plug-In EMBED Overflow Universal Exploit (MS06-006)
// By Matthew Murphy ([email protected])
//
// DISCLAIMER:
//
// This exploit code is intended only as a demonstration tool for
// educational or testing purposes. It is not intended to be used for any
// unauthorized or illicit purpose. Any testing done with this tool must
// be limited to systems that you own or are explicitly authorized to
// test.
//
// By utilizing or possessing this code, you assume any and all
// responsibility for damage that results. The author will not be held
// responsible, under any circumstances, for damage that arises from your
// possession or use of this code.
//
// Tested:
// Firefox
Exploit-DB
Microsoft Windows Media Player 9 - Plugin Overflow (MS06-006) (Metasploit)
exploitdb·2006-02-17
CVE-2006-0005 Microsoft Windows Media Player 9 - Plugin Overflow (MS06-006) (Metasploit)
Microsoft Windows Media Player 9 - Plugin Overflow (MS06-006) (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be redistributed
# according to the licenses defined in the Authors field below. In the
# case of an unknown or missing license, this file defaults to the same
# license as the core Framework (dual GPLv2 and Artistic). The latest
# version of the Framework can always be obtained from metasploit.com.
##
package Msf::Exploit::wmp_plugin_ms06_006;
use strict;
use base "Msf::Exploit";
use Pex::Text;
use IO::Socket::INET;
use IPC::Open3;
my $advanced =
{
'Gzip' => [1, 'Enable gzip content encoding'],
'Chunked' => [1, 'Enable chunked transfer encoding'],
};
my $info =
{
'Name' => 'Windows Media Player Plugin MS06-006 Overflow',
'Version' => '$Revision: 1
No writeups or analysis indexed.
http://secunia.com/advisories/18852http://securitytracker.com/id?1015628http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393http://www.kb.cert.org/vuls/id/692060http://www.securityfocus.com/bid/16644http://www.us-cert.gov/cas/techalerts/TA06-045A.htmlhttp://www.vupen.com/english/advisories/2006/0575https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-006https://exchange.xforce.ibmcloud.com/vulnerabilities/24493https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1559http://secunia.com/advisories/18852http://securitytracker.com/id?1015628http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393http://www.kb.cert.org/vuls/id/692060http://www.securityfocus.com/bid/16644http://www.us-cert.gov/cas/techalerts/TA06-045A.htmlhttp://www.vupen.com/english/advisories/2006/0575https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-006https://exchange.xforce.ibmcloud.com/vulnerabilities/24493https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1559
2006-02-14
Published
Exploited in the wild