Vulnerability record · CVE-2006-2379 · published 13 June 2006
CVE-2006-2379: Microsoft Windows TCP/IP driver buffer overflow via IP source routing
Microsoft · Windows 2000
The TCP/IP Protocol driver in Windows 2000 SP4, XP SP1/SP2, and Server 2003 SP1 and earlier contains a buffer overflow reachable through IP source routing. A remote attacker can trigger it to run arbitrary code with system privileges. The flaw is remotely reachable without authentication, making it a serious pre-auth network risk on unpatched hosts.
Description
Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated code execution with a CVSS 2.0 score of 9.3 and very high EPSS, though the affected platforms are long end-of-life and no KEV listing or known exploit is recorded.
What it is
The TCP/IP Protocol driver in Windows 2000 SP4, XP SP1/SP2, and Server 2003 SP1 and earlier contains a buffer overflow reachable through IP source routing. A remote attacker can trigger it to run arbitrary code with system privileges. The flaw is remotely reachable without authentication, making it a serious pre-auth network risk on unpatched hosts.
Impact
Successful exploitation gives the attacker arbitrary code execution in kernel context, typically resulting in full system compromise. No user interaction is required beyond the host being reachable on the network.
Attack surface
Reached over the network through the TCP/IP stack, specifically IP source routing handling, with no authentication required (AV:N/Au:N). The description does not specify whether any user action is needed, but the vector indicates none.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.5406 (98.9th percentile), indicating a high modeled likelihood of exploitation activity. Multiple references carry Patch tags, and no public exploit tag is present in the record.
What to do
- Apply Microsoft security bulletin MS06-032 (the vendor patch referenced in the record) to all affected Windows 2000, XP, and Server 2003 systems.
- Disable or filter IP source routing on hosts and at network boundaries where it is not operationally required.
- Block or restrict inbound IP source-routed packets at firewalls and routers to reduce exposure of unpatched systems.
- Isolate or upgrade end-of-life platforms (Windows 2000, XP, Server 2003) that can no longer receive vendor support.
- Verify patch deployment with the OVAL definitions referenced in the record.
Detection
- Monitor for anomalous or malformed IP source-routed packets arriving at Windows hosts.
- Alert on unexpected kernel-level crashes or reboots on affected Windows versions, which may indicate exploitation attempts.
- Correlate network IDS signatures for IP source routing abuse with host logs on unpatched systems.
- Audit patch state of Windows 2000, XP, and Server 2003 assets against MS06-032.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-2379 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-2379), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.