peter bassill · operator
$ cve CVE-2006-4704 JSON

CVE-2006-4704 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 43.9% (pctl 99)

Patch early

A public exploit exists.

Description

Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS43.85% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2006-11-01
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftvisual studio .net

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD