← Vulnerability feed

Vulnerability record · CVE-2006-0006 · published 14 February 2006

CVE-2006-0006: Windows Media Player bitmap heap buffer overflow

Microsoft · Windows Media Player

A heap-based buffer overflow exists in the bitmap processing routine of Windows Media Player. A crafted .BMP file that declares a size of 0 but carries additional data overflows the heap, allowing remote code execution. The flaw affects Media Player 7.1, 9, and 10 on Windows 2000 SP4, XP SP1, and XP SP2.

9.3 CVSS 2.0 High EPSS 50% · top 1.1% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
32References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote code execution with a 9.3 CVSS score and public exploit code, though the affected products are legacy and no KEV listing is present.

What it is

A heap-based buffer overflow exists in the bitmap processing routine of Windows Media Player. A crafted .BMP file that declares a size of 0 but carries additional data overflows the heap, allowing remote code execution. The flaw affects Media Player 7.1, 9, and 10 on Windows 2000 SP4, XP SP1, and XP SP2.

Impact

An attacker who gets the crafted bitmap processed can execute arbitrary code in the context of the user running Windows Media Player. Successful exploitation gives full control of the affected system.

Attack surface

Reached remotely over the network by delivering a malicious .BMP file to the victim; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required but some user interaction (opening or previewing the file) is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.49557 (98.8th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.

What to do

  • Apply the Microsoft security update for MS06-005 (the vendor patch referenced in the advisory).
  • Upgrade to a supported Windows and Windows Media Player release, since the affected versions are long out of support.
  • Block or strip .BMP attachments and downloads at email and web gateways where feasible.
  • Disable or restrict automatic handling and preview of image files in Windows Media Player and Explorer.
  • Educate users not to open unsolicited bitmap files from untrusted sources.

Detection

  • Monitor for Windows Media Player processes spawning unexpected child processes or making unusual network connections.
  • Hunt for .BMP files with a declared size of 0 that contain trailing data, using file format validation.
  • Review endpoint logs for crashes or heap corruption in wmplayer.exe or related media components.
  • Alert on exploit code or known PoC signatures associated with this vulnerability in network and endpoint sensors.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/18835 PatchVendor Advisory
http://securityreason.com/securityalert/423
http://securitytracker.com/id?1015627 Patch
http://www.eeye.com/html/research/advisories/AD20060214.html PatchVendor Advisory
http://www.kb.cert.org/vuls/id/291396 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/424983/100/0/threaded
http://www.securityfocus.com/archive/1/425158/100/0/threaded
http://www.securityfocus.com/bid/16633 ExploitPatch
http://www.us-cert.gov/cas/techalerts/TA06-045A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2006/0574 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-005
https://exchange.xforce.ibmcloud.com/vulnerabilities/24488
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1256
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1578
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1598
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1661
http://secunia.com/advisories/18835 PatchVendor Advisory
http://securityreason.com/securityalert/423
http://securitytracker.com/id?1015627 Patch
http://www.eeye.com/html/research/advisories/AD20060214.html PatchVendor Advisory
http://www.kb.cert.org/vuls/id/291396 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/424983/100/0/threaded
http://www.securityfocus.com/archive/1/425158/100/0/threaded
http://www.securityfocus.com/bid/16633 ExploitPatch
http://www.us-cert.gov/cas/techalerts/TA06-045A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2006/0574 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-005
https://exchange.xforce.ibmcloud.com/vulnerabilities/24488
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1256
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1578
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1598
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1661

Track CVE-2006-0006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2015-1701Microsoft Windows Win32k.sys Local Privilege EscalationWin32k.sys in the Windows kernel-mode drivers fails to properly validate input, allowing a local user to elevate privileges by running a crafted appl…KEVEPSS 56%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed7.8CVE-2010-0232Windows kernel exception handler privilege escalation via NTVDMThe Windows kernel fails to properly validate certain BIOS calls when 16-bit application support is enabled on 32-bit x86 systems. A local user can c…KEVEPSS 29%analysed7.8CVE-2009-1123Microsoft Windows kernel improper validation allows local privilege escalationThe Windows kernel fails to properly validate changes to unspecified kernel objects, letting a local user elevate privileges through a crafted applic…KEVEPSS 4.9%analysed7.8CVE-2004-0210Microsoft Windows POSIX component buffer overflow allows local code executionThe POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted …KEVEPSS 7.2%analysed

Source: NIST National Vulnerability Database (record CVE-2006-0006), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.