← back
CVE-2006-4868observed exploitation

CVE-2006-4868

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 60%
from disclosure to weapon5 days
Published on NVDSep 19
1st PoC+5d
metasploitSep 19
VulnCheck+7d
exploitation probability
60%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.