CVE-2006-4692 describes an argument injection vulnerability in the Windows Object Packager (packager.exe) affecting Microsoft Windows XP SP1/SP2 and Server 2003 SP1 and earlier. This flaw allows remote, user-assisted attackers to execute arbitrary commands by crafting a file with a slash character in the Command Line property's filename, leading to command execution before the slash. With a CVSS score of 5.1 (medium severity), exploitation requires high attack complexity (AC:H) but can result in partial confidentiality, integrity, and availability impacts (C:P/I:P/A:P). Despite its high FAUCET Risk Score of 97/100 and above-average EPSS, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.