cbcvebase.
CVE-2006-5745
published 2006-11-06

CVE-2006-5745: Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when…

PriorityP271high7.6CVSS 2.0
AVNACHAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
75.95%
99.5th percentile
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
ahnlabv3_internet_security
ahnlabv3_internet_security
aladdinesafe
avastavast_antivirus
avgantivirus
avgewido_security_suite
clamavclamav
clamavclamav
debianclamav
drwebanti-virus
esetnod32_antivirus
esetnod32_antivirus
esetsmart_security
ewidoewido_security_suite
fortinetfortiguard_antivirus
free-avantivir
free-avantivir
hacksoftthe_hacker
hacksoftthe_hacker
haurivirobot
haurivirobot
ikarusikarus_antivirus
ikarusikarus_antivirus
k7computingantivirus
k7computingantivirus

Detection & IOCsextracted from sources · hover to see the quote

filenameMicroHack.htm
bytes
%uE8FC%u0044%u0000%u458B%u8B3C%u057C%u0178%u8BEF%u184F%u5F8B%u0120%u49EB%u348B%u018B%u31EE%u99C0%u84AC%u74C0%uC107%u0DCA%uC201%uF4EB%u543B%u0424%uE575%u5F8B%u0124%u66EB%u0C8B%u8B4B%u1C5F%uEB01%u1C8B%u018B%u89EB%u245C%uC304%uC031%u8B64%u3040%uC085%u0C78%u408B%u8B0C%u1C70%u8BAD%u0868%u09EB%u808B%u00B0%u0000%u688B%u5F3C%uF631%u5660%uF889%uC083%u507B%u7E68%uE2D8%u6873%uFE98%u0E8A%uFF57%u63E7%u6C61%u0063
  • Exploit triggers via XMLHTTP ActiveX control's open() method called with Array objects followed by repeated setRequestHeader() calls with integer value 0x12345678 — detect this pattern in JavaScript within HTML documents.
  • Metasploit module uses return address 0x0c0c0c0c for heap spray on Windows 2000 SP4 through Windows 2003 SP0 targets — presence of this address in memory or network content is a strong indicator.
  • AV evasion technique: malicious HTML exploit document prefixed with MZ header (EXE magic bytes) and saved with no extension, .txt, or .jpg extension to bypass scanner detection.
  • The exploit targets the XMLHTTP ActiveX object (MSXML); look for object tags or ActiveXObject instantiation referencing MSXML followed by anomalous open()/setRequestHeader() call patterns.
  • ·Metasploit module randomizes all JavaScript variable names on each request, so static variable-name signatures will not reliably detect the server-generated exploit.
  • ·Metasploit module also applies whitespace randomization to the generated HTML content, further evading static/pattern-based detection.
  • ·The exploit was confirmed working on Windows 2000 SP4, Windows XP SP2, and Windows 2003 Server SP0 with IE6 and Microsoft XML Core Services 4.0 SP2; detection scope should be limited to these legacy platforms.

CVSS provenance

nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck2.6LOW
vendor_debian7.6LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.