Vulnerability record · CVE-2006-0021 · published 14 February 2006
CVE-2006-0021: Windows IGMP packet handling denial of service
Microsoft · Windows 2003 Server
Microsoft Windows XP SP1/SP2 and Server 2003 up to SP1 hang when they receive an IGMP packet carrying an invalid IP option. The flaw is a memory handling issue (CWE-119) in the IGMP processing path, and a single malformed packet is enough to take the system down.
Description
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityRemote, unauthenticated, low-complexity denial of service with public exploit references and very high EPSS, though limited to legacy Windows versions and no KEV listing.
What it is
Microsoft Windows XP SP1/SP2 and Server 2003 up to SP1 hang when they receive an IGMP packet carrying an invalid IP option. The flaw is a memory handling issue (CWE-119) in the IGMP processing path, and a single malformed packet is enough to take the system down.
Impact
A remote, unauthenticated attacker can cause a full denial of service, hanging the affected host and disrupting any services it provides. There is no reported confidentiality or integrity impact, only availability loss.
Attack surface
Reachable over the network via IGMP traffic sent to the target; the CVSS vector AV:N/AC:L/Au:N/C:N/I:N/A:C indicates no authentication and no user interaction are required. Any host that processes IGMP packets on the exposed interface is a candidate.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high (0.62882, 99th percentile) and public exploit references exist, so exploitation is plausible and tooling is available.
What to do
- Apply the Microsoft security update for MS06-007 on all affected Windows XP and Server 2003 systems.
- Where patching is not immediately possible, block or filter IGMP traffic at network boundaries and on host firewalls.
- Disable or restrict IGMP processing on hosts that do not require multicast group management.
- Segment networks so untrusted segments cannot send IGMP packets directly to critical Windows hosts.
- Verify patch level with the OVAL definitions referenced for this CVE.
Detection
- Monitor for unexpected IGMP traffic, especially packets with malformed or unusual IP options, at network sensors and host firewalls.
- Alert on sudden host unresponsiveness or hang events on Windows XP/Server 2003 systems that correlate with inbound IGMP traffic.
- Review firewall and IDS logs for IGMP packets originating from untrusted or external networks.
- Use the OVAL definitions for CVE-2006-0021 to continuously check patch compliance on affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0021 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0021), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.