CVE-2006-4446
published 2006-08-30CVE-2006-4446: Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a…
PriorityP269medium5CVSS 2.0
AVNACLAuNCNINAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
60.33%
99.0th percentile
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect instantiation of the vulnerable DirectAnimation.PathControl ActiveX object (ProgID: DirectAnimation.PathControl, CLSID: {D7A7D7C3-D47F-11D0-89D3-00A0C90833E6}) via script in a browser context, particularly calls to the Spline method with large/integer-overflow values such as 0xffffffff. ↗
- →Monitor for loading of daxctle.ocx as an ActiveX/COM InprocServer32 component within Internet Explorer processes, especially on Windows 2000 SP4, XP SP2, and 2003 SP1. ↗
- →The vulnerability is triggered via the Spline method of the DirectAnimation Path COM object; alert on heap-spray or large argument patterns passed to this method. ↗
- ·CVE-2006-4446 (Spline method, daxctle.ocx) is a distinct vulnerability from CVE-2006-4777 (KeyFrame method, daxctle.ocx); ensure detection rules target the correct method (Spline vs. KeyFrame) to avoid confusion between the two. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h8xv-8m4r-fp4f: Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-4777 [MEDIUM] CWE-119 GHSA-h8xv-8m4r-fp4f: Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.
GHSA
GHSA-4wjm-57gm-25fp: Heap-based buffer overflow in DirectAnimation
ghsa_unreviewed·2022-05-01
CVE-2006-4446 [MEDIUM] GHSA-4wjm-57gm-25fp: Heap-based buffer overflow in DirectAnimation
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.
GHSA
GHSA-3m9w-44xv-rc3v: Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-5884 [MEDIUM] GHSA-3m9w-44xv-rc3v: Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5
Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777.
VulnCheck
Microsoft Internet Explorer Out-of-bounds Write
vulncheck·2006·CVSS 5.0
CVE-2006-4446 [MEDIUM] Microsoft Internet Explorer Out-of-bounds Write
Microsoft Internet Explorer Out-of-bounds Write
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.
Affected: Microsoft Internet Explorer
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/SecurityBulletins/2006/ms06-067
VulnCheck
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2006·CVSS 5.0
CVE-2006-4777 [MEDIUM] Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.
Affected: Microsoft Internet Explorer
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/21910http://securityreason.com/securityalert/1468http://securitytracker.com/id?1016764http://www.osvdb.org/28841http://www.securityfocus.com/archive/1/444504/100/0/threadedhttp://www.securityfocus.com/bid/19738http://www.us-cert.gov/cas/techalerts/TA06-318A.htmlhttp://www.xsec.org/index.php?module=releases&act=view&type=1&id=19https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067https://exchange.xforce.ibmcloud.com/vulnerabilities/28608https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A437http://secunia.com/advisories/21910http://securityreason.com/securityalert/1468http://securitytracker.com/id?1016764http://www.osvdb.org/28841http://www.securityfocus.com/archive/1/444504/100/0/threadedhttp://www.securityfocus.com/bid/19738http://www.us-cert.gov/cas/techalerts/TA06-318A.htmlhttp://www.xsec.org/index.php?module=releases&act=view&type=1&id=19https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067https://exchange.xforce.ibmcloud.com/vulnerabilities/28608https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A437
2006-08-30
Published
Exploited in the wild