Vulnerability record · CVE-2006-0025 · published 13 June 2006
CVE-2006-0025: Windows Media Player PNG chunk size stack buffer overflow
Microsoft · Windows Media Player
Windows Media Player 9 and 10 contain a stack-based buffer overflow (CWE-119) triggered by a PNG image with a large chunk size. Because the flaw is reachable through media parsing and yields full code execution, it is a serious client-side risk for any system still running these versions.
Description
Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with full impact and has a very high EPSS score, but it is an old, patched issue with no KEV listing or documented ransomware use.
What it is
Windows Media Player 9 and 10 contain a stack-based buffer overflow (CWE-119) triggered by a PNG image with a large chunk size. Because the flaw is reachable through media parsing and yields full code execution, it is a serious client-side risk for any system still running these versions.
Impact
A remote attacker can execute arbitrary code in the context of the user running Windows Media Player. Successful exploitation gives full control of confidentiality, integrity and availability on the affected host.
Attack surface
Reached remotely over the network (AV:N) by delivering a crafted PNG to the victim, typically via a web page, email or file share. No authentication is required, but the CVSS vector indicates medium attack complexity and some form of user interaction is needed to open or render the image.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.48723, 98.8th percentile), and multiple references carry Patch/Vendor Advisory tags, indicating a known, patchable issue rather than confirmed in-the-wild exploitation.
What to do
- Apply Microsoft security bulletin MS06-024 (the vendor patch for this issue) to all affected Windows Media Player 9 and 10 installations.
- Upgrade to a supported Windows Media Player version or a supported Windows release where the affected component is no longer present.
- Restrict or block untrusted PNG files from being opened in Windows Media Player where business processes allow.
- Reduce exposure by limiting user rights and applying network controls so untrusted media cannot be delivered to endpoints that still run the vulnerable player.
Detection
- Monitor for Windows Media Player processes (wmplayer.exe) spawning child processes or making unexpected network connections, which can indicate successful exploitation.
- Hunt for crash or exception events in Windows Media Player when opening PNG files, especially repeated failures tied to media parsing.
- Inspect email and web proxy logs for PNG attachments or downloads directed at users who still run Windows Media Player 9 or 10.
- Use the OVAL definitions referenced for this CVE to check endpoint patch state and flag unpatched Windows Media Player installations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0025 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0025), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.