Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-4692

25
FAUCET Score

CVE-2006-4692 describes an argument injection vulnerability in the Windows Object Packager (packager.exe) affecting Microsoft Windows XP SP1/SP2 and Server 2003 SP1 and earlier. This flaw allows remote, user-assisted attackers to execute arbitrary commands by crafting a file with a slash character in the Command Line property's filename, leading to command execution before the slash. With a CVSS score of 5.1 (medium severity), exploitation requires high attack complexity (AC:H) but can result in partial confidentiality, integrity, and availability impacts (C:P/I:P/A:P). Despite its high FAUCET Risk Score of 97/100 and above-average EPSS, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2003:-:-:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2003:-:sp1:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.1MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
27.70%
Probability of exploitation in next 30 days
EPSS Percentile
97.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.2770 is in the 98th percentile among its peer group of 19,958 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

docs.microsoft.com / en-us/security-updates/securitybulletins/2006/ms06-065
PatchVendor Advisory
secunia.com / advisories/20717
Broken LinkVendor Advisory
secunia.com / secunia_research/2006-54/advisory
Broken LinkVendor Advisory
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A496
Broken Link
kb.cert.org / vuls/id/703936
Third Party AdvisoryUS Government Resource
osvdb.org / 29424
Broken Link
securityfocus.com / archive/1/448273/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/448696/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/449179/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/20318
Broken LinkThird Party AdvisoryVDB Entry
vupen.com / english/advisories/2006/3984
Broken LinkVendor Advisory