Vulnerability record · CVE-2006-0006 · published 14 February 2006
CVE-2006-0006: Windows Media Player bitmap heap buffer overflow
Microsoft · Windows Media Player
A heap-based buffer overflow exists in the bitmap processing routine of Windows Media Player. A crafted .BMP file that declares a size of 0 but carries additional data overflows the heap, allowing remote code execution. The flaw affects Media Player 7.1, 9, and 10 on Windows 2000 SP4, XP SP1, and XP SP2.
Description
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with a 9.3 CVSS score and public exploit code, though the affected products are legacy and no KEV listing is present.
What it is
A heap-based buffer overflow exists in the bitmap processing routine of Windows Media Player. A crafted .BMP file that declares a size of 0 but carries additional data overflows the heap, allowing remote code execution. The flaw affects Media Player 7.1, 9, and 10 on Windows 2000 SP4, XP SP1, and XP SP2.
Impact
An attacker who gets the crafted bitmap processed can execute arbitrary code in the context of the user running Windows Media Player. Successful exploitation gives full control of the affected system.
Attack surface
Reached remotely over the network by delivering a malicious .BMP file to the victim; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required but some user interaction (opening or previewing the file) is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.49557 (98.8th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.
What to do
- Apply the Microsoft security update for MS06-005 (the vendor patch referenced in the advisory).
- Upgrade to a supported Windows and Windows Media Player release, since the affected versions are long out of support.
- Block or strip .BMP attachments and downloads at email and web gateways where feasible.
- Disable or restrict automatic handling and preview of image files in Windows Media Player and Explorer.
- Educate users not to open unsolicited bitmap files from untrusted sources.
Detection
- Monitor for Windows Media Player processes spawning unexpected child processes or making unusual network connections.
- Hunt for .BMP files with a declared size of 0 that contain trailing data, using file format validation.
- Review endpoint logs for crashes or heap corruption in wmplayer.exe or related media components.
- Alert on exploit code or known PoC signatures associated with this vulnerability in network and endpoint sensors.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0006 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0006), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.