Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll),...
Vulnerability Description
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4868
Credits & Attribution
No credits recorded in the NVD database.
References
- http://blogs.securiteam.com/index.php/archives/624
- http://www.securityfocus.com/archive/1/446881/100/200/threaded
- http://www.securityfocus.com/bid/20096
- http://www.securityfocus.com/archive/1/446523/100/0/threaded
- http://www.securityfocus.com/archive/1/446505/100/0/threaded
- http://www.vupen.com/english/advisories/2006/3679
- http://www.kb.cert.org/vuls/id/416092
- http://www.microsoft.com/technet/security/advisory/925568.mspx
- http://support.microsoft.com/kb/925486
- http://secunia.com/advisories/21989
- http://www.securityfocus.com/archive/1/448552/100/0/threaded
- http://www.securityfocus.com/archive/1/448552/100/0/threaded
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-055
- http://www.us-cert.gov/cas/techalerts/TA06-262A.html
- http://www.securityfocus.com/archive/1/446528/100/0/threaded
- http://www.osvdb.org/28946
- http://securitytracker.com/id?1016879
- http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html
- http://www.securityfocus.com/archive/1/447070/100/0/threaded
- http://www.securityfocus.com/archive/1/446378/100/0/threaded
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29004
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.