peter bassill · operator
$ cve CVE-2006-6296 JSON

CVE-2006-6296 EXPLOIT

6.1
MEDIUM · CVSS 2.0 · EPSS 22% (pctl 98)

Patch early

A public exploit exists.

Description

The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.

Scoring

CVSS6.1 (MEDIUM, v2.0)
VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
EPSS21.98% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2006-12-05
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftwindows 2000
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD