CVE-2006-4868 describes a stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll) affecting Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, among other versions. This critical vulnerability (CVSS 9.3) allows remote attackers to execute arbitrary code by crafting a malicious Vector Markup Language (VML) file with an excessively long fill parameter within a rect tag. Exploitation requires user interaction (e.g., opening a malicious email or visiting a compromised website), but successful attacks lead to complete compromise of confidentiality, integrity, and availability. While not on the CISA KEV catalog, exploit modules exist in Metasploit and ExploitDB, indicating readily available exploit code, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.