Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-4704

58
FAUCET Score

CVE-2006-4704 is a cross-zone scripting vulnerability in the WMI Object Broker ActiveX control (WMIScriptUtils.WMIObjectBroker2) within Microsoft Visual Studio 2005. This flaw allows remote attackers to bypass Internet zone restrictions, leading to arbitrary code execution by instantiating dangerous objects. The vulnerability has a CVSS score of 6.8, indicating a medium severity with network access, medium attack complexity, and partial impact on confidentiality, integrity, and availability. While not currently on CISA's KEV catalog, exploit modules exist in Metasploit (MS06-014), and its high EPSS and FAUCET risk scores suggest a significant potential for exploitation despite minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
2005CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_.net:2005:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
42.85%
Probability of exploitation in next 30 days
EPSS Percentile
98.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Metasploit: MS06-014 Microsoft Internet Explorer COM CreateObject Code Execution · Apr 11, 2006
ExploitDB: EDB-16561 · Sep 20, 2010
This CVE's current EPSS score of 0.4285 is in the 99th percentile among its peer group of 19,955 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

microsoftvendor investigatingvia nvd_reference
View patch

References

blogs.technet.com / msrc/archive/2006/11/01/microsoft-security-advisory-927709-posted.aspx
research.eeye.com / html/alerts/zeroday/20061031.html
docs.microsoft.com / en-us/security-updates/securitybulletins/2006/ms06-073
secunia.com / advisories/22603
Vendor Advisory
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/29915
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A288
kb.cert.org / vuls/id/854856
US Government Resource
microsoft.com / technet/security/advisory/927709.mspx
Vendor Advisory
securityfocus.com / archive/1/454201/100/0/threaded
securityfocus.com / archive/1/454969/100/200/threaded
securityfocus.com / bid/20797
securityfocus.com / bid/20843
Exploit
securityfocus.com / data/vulnerabilities/exploits/0day_ie.pdf
us-cert.gov / cas/techalerts/TA06-346A.html
US Government Resource
vupen.com / english/advisories/2006/4282
Vendor Advisory
zerodayinitiative.com / advisories/ZDI-06-047.html