peter bassill · operator
$ cve CVE-2006-4691 JSON

CVE-2006-4691 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 78.9% (pctl 100)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS78.94% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2006-11-14
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftwindows 2000
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD