Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-2379

CWE-119Buffer Overflow4 documents4 sources
Severity
9.3CRITICAL
EPSS
79.4%
top 0.92%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 13
Latest updateMay 1

Description

Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fh4x-hv33-xh3g: Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers t2022-05-01
CVEList
CVE-2006-2379: Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers t2006-06-13

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - TCP/IP Protocol Driver Remote Buffer Overflow2006-06-30
CVE-2006-2379 (CRITICAL CVSS 9.3) | Buffer overflow in the TCP/IP Proto | cvebase.io