CVE-2006-0005

UnknownEPSS 43.59%

Last modified

CVE-2006-0005 is a vulnerability of currently unknown severity. Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.. EPSS estimates a 43.59% chance of exploitation in the next 30 days.

Description

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.

Metrics

EPSS Probability
43.59%

98.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
MicrosoftWindows-Ntdatacenter_server
MicrosoftWindows-NtxpSp2
MicrosoftWindows-Ntxp_tablet_pc
MicrosoftWindows 2000All versionsSp1
MicrosoftWindows 2000 Advanced ServerAll versions
MicrosoftWindows 2000 Advanced Serversp1
MicrosoftWindows 2000 Advanced Serversp2
MicrosoftWindows 2000 Advanced Serversp3
MicrosoftWindows 2000 Advanced Serversp4
MicrosoftWindows 2003 Serverdatacenter_edition
MicrosoftWindows 2003 Serverdatacenter_edition_64-bit
MicrosoftWindows 2003 Serverenterprise_edition
MicrosoftWindows 2003 Serverenterprise_edition_64-bit
MicrosoftWindows 2003 Serverstandard
MicrosoftWindows 2003 Serverstandard_64-bit
MicrosoftWindows 2003 Serverweb_edition
MicrosoftWindows Server 2000none
MicrosoftWindows Server 2000sp1
MicrosoftWindows Server 2000sp2
MicrosoftWindows Server 2000sp3
MicrosoftWindows Server 2003datacenter_sp1
MicrosoftWindows Server 2003enterprise_sp1
MicrosoftWindows Server 2003standard_sp1
MicrosoftWindows Server 2003web_edition_sp1
MicrosoftWindows XpAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-0005?
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
How severe is CVE-2006-0005?
Severity scoring for CVE-2006-0005 is pending analysis. The EPSS model estimates a 43.59% probability of exploitation in the next 30 days.
How do I fix CVE-2006-0005?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-0005?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST