CVE-2006-4691 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 78.9% (pctl 100)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 78.94% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-11-14 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows 2000 |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Workstation Service - NetpManageIPCConnect Overflow (MS06-070) (Metasploit) | 2010-10-05 |
| exploit-db | Microsoft Windows - 'NetpManageIPCConnect' Remote Stack Overflow (MS06-070) | 2006-11-18 |
| exploit-db | Microsoft Windows - Wkssvc NetrJoinDomain2 Stack Overflow (MS06-070) | 2006-11-17 |
| exploit-db | Microsoft Windows - NetpManageIPCConnect Stack Overflow (MS06-070) | 2006-11-16 |
References
- http://research.eeye.com/html/advisories/published/AD20061114.html
- http://secunia.com/advisories/22883
- http://securitytracker.com/id?1017221
- http://www.kb.cert.org/vuls/id/778036
- http://www.securityfocus.com/archive/1/451588/100/0/threaded
- http://www.securityfocus.com/bid/20985
- http://www.us-cert.gov/cas/techalerts/TA06-318A.html
- http://www.vupen.com/english/advisories/2006/4508
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-070
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29948
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A607
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A908
- http://research.eeye.com/html/advisories/published/AD20061114.html
- http://secunia.com/advisories/22883
- http://securitytracker.com/id?1017221
- http://www.kb.cert.org/vuls/id/778036
- http://www.securityfocus.com/archive/1/451588/100/0/threaded
- http://www.securityfocus.com/bid/20985
- http://www.us-cert.gov/cas/techalerts/TA06-318A.html
- http://www.vupen.com/english/advisories/2006/4508
→ the Explorer · watch your stack · NVD