cbcvebase.
CVE-2006-4777
published 2006-09-14

CVE-2006-4777: Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese…

PriorityP269high7.6CVSS 2.0
AVNACHAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
78.75%
99.5th percentile
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftie
microsoftie
microsoftinternet_explorer
microsoftinternet_explorer

Detection & IOCsextracted from sources · hover to see the quote

filenamedaxctle.ocx
filenamexsec.htm
otherDirectAnimation.PathControl
other0x4058b5
bytes
\xe9\xa3\x00\x00\x00\x5f\x64\xa1\x30\x00\x00\x00\x8b\x40\x0c\x8b\x70\x1c\xad\x8b\x68\x08\x8b\xf7\x6a\x04\x59\xe8\x43\x00\x00\x00\xe2\xf9\x68\x6f\x6e\x00\x00\x68\x75\x72\x6c\x6d\x54\xff\x16\x95\xe8\x2e\x00\x00\x00\x83\xec\x20\x8b\xdc\x6a\x20\x53\xff\x56\x04\xc7\x04\x03\x5c\x61\x2e\x65\xc7\x44\x03\x04\x78\x65\x00\x00\x33\xc0\x50\x50\x53\x57\x50\xff\x56\x10\x8b\xdc\x50\x53\xff\x56\x08\xff\x56\x0c\x51\x56\x8b\x75\x3c\x8b\x74\x2e\x78\x03\xf5\x56\x8b\x76\x20\x03\xf5\x33\xc9\x49\x41\xad\x03\xc5\x33\xdb\x0f\xbe\x10\x3a\xd6\x74\x08\xc1\xcb\x0d\x03\xda\x40\xeb\xf1\x3b\x1f\x75\xe7\x5e\x8b\x5e\x24\x03\xdd\x66\x8b\x0c\x4b\x8b\x5e\x1c\x03\xdd\x8b\x04\x8b\x03\xc5\xab\x5e\x59\xc3\xe8\x58\xff\xff\xff\x8e\x4e\x0e\xec\xc1\x79\xe5\xb8\x98\xfe\x8a\x0e\xef\xce\xe0\x60\x36\x1a\x2f\x70
  • Detect instantiation of the vulnerable DirectAnimation.PathControl ActiveX COM object (CLSID daxctle.ocx) in HTML/script content, particularly followed by calls to the KeyFrame method.
  • Monitor for creation or loading of daxctle.ocx by iexplore.exe processes, especially on Windows 2000/XP/2003 systems running IE 6.0 SP1.
  • ·The vulnerability is reported to affect primarily Chinese Windows distributions; exploitation reliability on other locales may vary.
  • ·The Metasploit module payload space is constrained to 870 bytes by heaplib; payloads exceeding this size will not function correctly.
  • ·Exploitation on Windows XP SP2 CN requires luck due to heap layout unpredictability; the exploit is more reliable on Windows 2000 Server SP4 CN.
  • ·This CVE is a different vulnerability from CVE-2006-4446, though both affect daxctle.ocx; detection rules should not conflate the two.

CVSS provenance

nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.