← Vulnerability feed

Vulnerability record · CVE-2006-0025 · published 13 June 2006

CVE-2006-0025: Windows Media Player PNG chunk size stack buffer overflow

Microsoft · Windows Media Player

Windows Media Player 9 and 10 contain a stack-based buffer overflow (CWE-119) triggered by a PNG image with a large chunk size. Because the flaw is reachable through media parsing and yields full code execution, it is a serious client-side risk for any system still running these versions.

9.3 CVSS 2.0 High EPSS 49% · top 1.2% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityThe flaw allows remote code execution with full impact and has a very high EPSS score, but it is an old, patched issue with no KEV listing or documented ransomware use.

What it is

Windows Media Player 9 and 10 contain a stack-based buffer overflow (CWE-119) triggered by a PNG image with a large chunk size. Because the flaw is reachable through media parsing and yields full code execution, it is a serious client-side risk for any system still running these versions.

Impact

A remote attacker can execute arbitrary code in the context of the user running Windows Media Player. Successful exploitation gives full control of confidentiality, integrity and availability on the affected host.

Attack surface

Reached remotely over the network (AV:N) by delivering a crafted PNG to the victim, typically via a web page, email or file share. No authentication is required, but the CVSS vector indicates medium attack complexity and some form of user interaction is needed to open or render the image.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.48723, 98.8th percentile), and multiple references carry Patch/Vendor Advisory tags, indicating a known, patchable issue rather than confirmed in-the-wild exploitation.

What to do

  • Apply Microsoft security bulletin MS06-024 (the vendor patch for this issue) to all affected Windows Media Player 9 and 10 installations.
  • Upgrade to a supported Windows Media Player version or a supported Windows release where the affected component is no longer present.
  • Restrict or block untrusted PNG files from being opened in Windows Media Player where business processes allow.
  • Reduce exposure by limiting user rights and applying network controls so untrusted media cannot be delivered to endpoints that still run the vulnerable player.

Detection

  • Monitor for Windows Media Player processes (wmplayer.exe) spawning child processes or making unexpected network connections, which can indicate successful exploitation.
  • Hunt for crash or exception events in Windows Media Player when opening PNG files, especially repeated failures tied to media parsing.
  • Inspect email and web proxy logs for PNG attachments or downloads directed at users who still run Windows Media Player 9 or 10.
  • Use the OVAL definitions referenced for this CVE to check endpoint patch state and flag unpatched Windows Media Player installations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/20626 PatchVendor Advisory
http://securitytracker.com/id?1016284
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/608020 US Government Resource
http://www.osvdb.org/26430
http://www.securityfocus.com/bid/18385 Patch
http://www.us-cert.gov/cas/techalerts/TA06-164A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2322
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-024
https://exchange.xforce.ibmcloud.com/vulnerabilities/26788
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1230
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1729
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1805
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1807
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1820
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1974
http://secunia.com/advisories/20626 PatchVendor Advisory
http://securitytracker.com/id?1016284
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/608020 US Government Resource
http://www.osvdb.org/26430
http://www.securityfocus.com/bid/18385 Patch
http://www.us-cert.gov/cas/techalerts/TA06-164A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2322
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-024
https://exchange.xforce.ibmcloud.com/vulnerabilities/26788
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1230
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1729
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1805
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1807
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1820
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1974

Track CVE-2006-0025 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3009Microsoft windows media player vulnerabilityMicrosoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the …EPSS 16%10.0CVE-2008-3010Microsoft windows media player information exposure vulnerabilityMicrosoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP ad…EPSS 15%10.0CVE-2004-0597libpng PNG chunk buffer overflows allow remote code executionlibpng 1.2.5 and earlier contain multiple buffer overflows in the png_handle_tRNS, png_handle_sBIT and png_handle_hIST functions, which fail to valid…EPSS 83%analysed9.3CVE-2015-1728Microsoft windows media player vulnerabilityMicrosoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "Windows M…EPSS 18%9.3CVE-2013-3127Microsoft windows media format runtime code injection vulnerabilityThe Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime…EPSS 22%9.3CVE-2010-2745Microsoft windows media player code injection vulnerabilityMicrosoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted rem…EPSS 24%9.3CVE-2010-3138Microsoft windows media player vulnerabilityUntrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan …EPSS 27%9.3CVE-2010-0268Microsoft windows media player vulnerabilityUnspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2006-0025), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.