Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-0005

CWE-119Buffer Overflow8 documents5 sources
Severity
9.3CRITICAL
EPSS
75.5%
top 1.11%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedFeb 14
Latest updateMay 1

Description

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

NVDmicrosoft/windows8 versions+7
NVDmicrosoft/windows-ntdatacenter_server, xp, xp_tablet_pc+2

🔴Vulnerability Details

3
GHSA
GHSA-6h2j-xchg-wcx8: Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the de2022-05-01
CVEList
CVE-2006-0005: Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the de2006-02-14
VulnCheck
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer2006

💥Exploits & PoCs

4
Exploit-DB
Man Command - -H Flag Local Buffer Overflow2007-04-06
Exploit-DB
Microsoft Windows Media Player - Plugin Overflow (MS06-006) (3)2006-02-22
Exploit-DB
Microsoft Windows Media Player 10 - Plugin Overflow (MS06-006)2006-02-17
Exploit-DB
Microsoft Windows Media Player 9 - Plugin Overflow (MS06-006) (Metasploit)2006-02-17
CVE-2006-0005 (CRITICAL CVSS 9.3) | Buffer overflow in the plug-in for | cvebase.io