CVE-2006-0005 describes a buffer overflow vulnerability in the Microsoft Windows Media Player (WMP) 9 and 10 plug-in, affecting various Windows operating systems. This flaw allows remote attackers to execute arbitrary code when WMP is the default media handler in non-Internet Explorer browsers, by embedding a long 'src' attribute within an HTML EMBED element. With a CVSS score of 9.3, it is a critical vulnerability, indicating network-based attacks with medium complexity can lead to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit code is publicly available on ExploitDB, including a Metasploit module. Despite the existence of exploits, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
datacenter_serverCPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:datacenter_server:*:*:*:*:*:*:* | ||
datacenter_serverCPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp1:*:*:*:*:*:* | ||
datacenter_serverCPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp2:*:*:*:*:*:* | ||
datacenter_serverCPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp3:*:*:*:*:*:* | ||
datacenter_serverCPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.