Vulnerability record · CVE-2006-4777 · published 14 September 2006
CVE-2006-4777: Internet Explorer DirectAnimation PathControl COM object heap buffer overflow
Microsoft · Ie
The DirectAnimation.PathControl COM object (daxctle.ocx) in Internet Explorer 6.0 SP1 contains a heap-based buffer overflow reachable through the KeyFrame method, possibly involving an integer overflow. Successful exploitation allows remote code execution in the context of the browsing user, and the flaw is distinct from CVE-2006-4446.
Description
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete impact and a very high EPSS score, though the high access complexity and the age of the affected product temper the rating.
What it is
The DirectAnimation.PathControl COM object (daxctle.ocx) in Internet Explorer 6.0 SP1 contains a heap-based buffer overflow reachable through the KeyFrame method, possibly involving an integer overflow. Successful exploitation allows remote code execution in the context of the browsing user, and the flaw is distinct from CVE-2006-4446.
Impact
An attacker can execute arbitrary code with the privileges of the user running Internet Explorer, leading to full compromise of the client. The CVSS vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached over the network via a crafted web page or content that instantiates the DirectAnimation PathControl COM object and passes manipulated arguments to KeyFrame; no authentication is required, but the CVSS vector marks access complexity as high, implying some conditions or user interaction are needed to trigger it.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.798, 99.6th percentile), indicating substantial observed or predicted exploitation activity; references include vendor advisories and US-CERT alerts.
What to do
- Apply Microsoft security bulletin MS06-067, which addresses this vulnerability, or the later cumulative Internet Explorer update for the affected platform.
- Disable or block the DirectAnimation PathControl COM object (daxctle.ocx) via the kill-bit mechanism if patching is not immediately possible.
- Restrict or disable ActiveX execution in Internet Explorer for untrusted sites and enforce zone-based controls.
- Upgrade from Internet Explorer 6.0 SP1 to a supported browser version, since the affected product is long out of support.
- Apply the Microsoft security advisory 925444 workarounds where applicable.
Detection
- Monitor for Internet Explorer processes loading daxctle.ocx, especially from unexpected paths or after visiting untrusted sites.
- Hunt for crashes or heap corruption events in iexplore.exe correlated with ActiveX instantiation of DirectAnimation controls.
- Alert on network downloads of pages or objects that reference DirectAnimation.PathControl or the KeyFrame method.
- Use the OVAL definition oval:org.mitre.oval:def:1103 to check for the vulnerable state on endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-4777 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-4777), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.