← Vulnerability feed

Vulnerability record · CVE-2006-4868 · published 19 September 2006

CVE-2006-4868: Microsoft VML vgx.dll stack buffer overflow via long fill parameter

Microsoft · Internet Explorer

The Vector Graphics Rendering engine (vgx.dll) used by Microsoft Internet Explorer 6.0 and Outlook on Windows XP SP2 contains a stack-based buffer overflow. A VML file with an overly long fill parameter inside a rect tag overflows a stack buffer, allowing remote code execution. The flaw is remotely reachable and was exploited in the wild as a zero-day before patching.

9.3 CVSS 2.0 High EPSS 61% · top 0.9% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
42References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.3, high EPSS, and confirmed in-the-wild zero-day exploitation make this a critical remote code execution flaw.

What it is

The Vector Graphics Rendering engine (vgx.dll) used by Microsoft Internet Explorer 6.0 and Outlook on Windows XP SP2 contains a stack-based buffer overflow. A VML file with an overly long fill parameter inside a rect tag overflows a stack buffer, allowing remote code execution. The flaw is remotely reachable and was exploited in the wild as a zero-day before patching.

Impact

An attacker can execute arbitrary code in the context of the affected application, giving full control of the victim's system. Successful exploitation can lead to malware installation, data theft, or further compromise.

Attack surface

Reached remotely over the network via a crafted VML document rendered by Internet Explorer 6.0 or Outlook; no authentication is required, but some user interaction (viewing a malicious page or email) is typically needed. The CVSS vector AV:N/AC:M/Au:N confirms network reachability with medium complexity and no authentication.

Exploitation

Public references include an Exploit tag and a blog noting a zero-day exploit seen in the wild, and EPSS is 0.6144 (99.1st percentile), indicating high likelihood of exploitation. The CVE is not listed in CISA KEV.

What to do

  • Apply Microsoft security update MS06-055 (KB925486) to affected Windows XP SP2 systems.
  • Disable or unregister vgx.dll where VML rendering is not required.
  • Block or filter VML content in email and web traffic until patching is complete.
  • Restrict browsing and email clients to trusted sites and disable active content where feasible.

Detection

  • Monitor for processes loading vgx.dll and spawning unexpected child processes.
  • Inspect network and email traffic for VML files containing rect tags with unusually long fill parameters.
  • Review endpoint logs for crashes in Internet Explorer or Outlook related to vgx.dll.
  • Hunt for known exploit artifacts referenced in public exploit and vendor advisory sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.securiteam.com/index.php/archives/624
http://secunia.com/advisories/21989 PatchVendor Advisory
http://securitytracker.com/id?1016879
http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html
http://support.microsoft.com/kb/925486
http://www.kb.cert.org/vuls/id/416092 US Government Resource
http://www.microsoft.com/technet/security/advisory/925568.mspx PatchVendor Advisory
http://www.osvdb.org/28946
http://www.securityfocus.com/archive/1/446378/100/0/threaded
http://www.securityfocus.com/archive/1/446505/100/0/threaded
http://www.securityfocus.com/archive/1/446523/100/0/threaded
http://www.securityfocus.com/archive/1/446528/100/0/threaded
http://www.securityfocus.com/archive/1/446881/100/200/threaded
http://www.securityfocus.com/archive/1/447070/100/0/threaded
http://www.securityfocus.com/archive/1/448552/100/0/threaded
http://www.securityfocus.com/bid/20096 ExploitPatch
http://www.us-cert.gov/cas/techalerts/TA06-262A.html PatchUS Government Resource
http://www.vupen.com/english/advisories/2006/3679 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-055
https://exchange.xforce.ibmcloud.com/vulnerabilities/29004
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100
http://blogs.securiteam.com/index.php/archives/624
http://secunia.com/advisories/21989 PatchVendor Advisory
http://securitytracker.com/id?1016879
http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html
http://support.microsoft.com/kb/925486
http://www.kb.cert.org/vuls/id/416092 US Government Resource
http://www.microsoft.com/technet/security/advisory/925568.mspx PatchVendor Advisory
http://www.osvdb.org/28946
http://www.securityfocus.com/archive/1/446378/100/0/threaded
http://www.securityfocus.com/archive/1/446505/100/0/threaded
http://www.securityfocus.com/archive/1/446523/100/0/threaded
http://www.securityfocus.com/archive/1/446528/100/0/threaded
http://www.securityfocus.com/archive/1/446881/100/200/threaded
http://www.securityfocus.com/archive/1/447070/100/0/threaded
http://www.securityfocus.com/archive/1/448552/100/0/threaded
http://www.securityfocus.com/bid/20096 ExploitPatch
http://www.us-cert.gov/cas/techalerts/TA06-262A.html PatchUS Government Resource
http://www.vupen.com/english/advisories/2006/3679 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-055

Track CVE-2006-4868 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed9.8CVE-2015-0311Adobe Flash Player unspecified flaw allows remote code executionCVE-2015-0311 is an unspecified vulnerability in Adobe Flash Player affecting versions through 13.0.0.262, 14.x, 15.x, and 16.x through 16.0.0.287 on…KEVEPSS 86%analysed9.8CVE-2014-1776Internet Explorer use-after-free in CMarkup::IsConnectedToPrimaryMarkupMicrosoft Internet Explorer 6 through 11 contains a use-after-free in the CMarkup::IsConnectedToPrimaryMarkup function that allows remote code execut…KEVEPSS 83%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2021-27085Microsoft Internet Explorer remote code execution flawCVE-2021-27085 is a remote code execution vulnerability in Microsoft Internet Explorer. The record gives only a one-line description and no root-caus…KEVEPSS 5.4%analysed8.8CVE-2021-26411Microsoft Internet Explorer and Edge use-after-free memory corruptionCVE-2021-26411 is a use-after-free (CWE-416) memory corruption flaw in Microsoft Internet Explorer, with Microsoft Edge also listed as an affected pr…KEVEPSS 81%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2006-4868), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.