Vulnerability record · CVE-2006-4688 · published 14 November 2006
CVE-2006-4688: Windows Client Service for NetWare buffer overflow allows remote code execution
Microsoft · Windows 2000
Client Service for NetWare (CSNW) in Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 contains a buffer overflow that can be triggered by crafted messages. Successful exploitation allows arbitrary code execution on the affected system. The flaw is remotely reachable and requires no authentication.
Description
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a high EPSS score, though the affected operating systems are legacy and no KEV listing is present.
What it is
Client Service for NetWare (CSNW) in Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 contains a buffer overflow that can be triggered by crafted messages. Successful exploitation allows arbitrary code execution on the affected system. The flaw is remotely reachable and requires no authentication.
Impact
A remote attacker can execute arbitrary code with the privileges of the vulnerable service, potentially leading to full system compromise. The CVSS vector indicates partial confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no authentication required (AC:L/Au:N). No user interaction is indicated by the vector or description.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation activity (0.75022, 99.48th percentile). No public exploit references are tagged in the supplied data.
What to do
- Apply the Microsoft security update MS06-066 immediately.
- Disable or remove Client Service for NetWare (CSNW) on systems that do not require it.
- Block NetWare-related ports at network boundaries where feasible.
- Monitor for and restrict unnecessary network access to affected Windows hosts.
Detection
- Monitor for unexpected crashes or restarts of the CSNW service.
- Inspect network traffic for anomalous NetWare protocol messages targeting affected hosts.
- Review system logs for signs of code execution or privilege escalation following CSNW activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-4688 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-4688), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.