CVE-2006-0005 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 38.7% (pctl 99)
Patch early
A public exploit exists.
Description
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 38.67% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-02-14 |
| Last modified | 2026-06-16 |
Affected (7)
| Vendor | Product |
|---|---|
| microsoft | windows 2000 |
| microsoft | windows 2000 advanced server |
| microsoft | windows 2003 server |
| microsoft | windows server 2000 |
| microsoft | windows server 2003 |
| microsoft | windows xp |
| microsoft | windows-nt |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows Media Player - Plugin Overflow (MS06-006) (3) | 2006-02-22 |
| exploit-db | Microsoft Windows Media Player 9 - Plugin Overflow (MS06-006) (Metasploit) | 2006-02-17 |
| exploit-db | Microsoft Windows Media Player 10 - Plugin Overflow (MS06-006) | 2006-02-17 |
References
- http://secunia.com/advisories/18852
- http://securitytracker.com/id?1015628
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393
- http://www.kb.cert.org/vuls/id/692060
- http://www.securityfocus.com/bid/16644
- http://www.us-cert.gov/cas/techalerts/TA06-045A.html
- http://www.vupen.com/english/advisories/2006/0575
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-006
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24493
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1559
- http://secunia.com/advisories/18852
- http://securitytracker.com/id?1015628
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393
- http://www.kb.cert.org/vuls/id/692060
- http://www.securityfocus.com/bid/16644
- http://www.us-cert.gov/cas/techalerts/TA06-045A.html
- http://www.vupen.com/english/advisories/2006/0575
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-006
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24493
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1559
→ the Explorer · watch your stack · NVD