Vulnerability record · CVE-2006-4868 · published 19 September 2006
CVE-2006-4868: Microsoft VML vgx.dll stack buffer overflow via long fill parameter
Microsoft · Internet Explorer
The Vector Graphics Rendering engine (vgx.dll) used by Microsoft Internet Explorer 6.0 and Outlook on Windows XP SP2 contains a stack-based buffer overflow. A VML file with an overly long fill parameter inside a rect tag overflows a stack buffer, allowing remote code execution. The flaw is remotely reachable and was exploited in the wild as a zero-day before patching.
Description
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 9.3, high EPSS, and confirmed in-the-wild zero-day exploitation make this a critical remote code execution flaw.
What it is
The Vector Graphics Rendering engine (vgx.dll) used by Microsoft Internet Explorer 6.0 and Outlook on Windows XP SP2 contains a stack-based buffer overflow. A VML file with an overly long fill parameter inside a rect tag overflows a stack buffer, allowing remote code execution. The flaw is remotely reachable and was exploited in the wild as a zero-day before patching.
Impact
An attacker can execute arbitrary code in the context of the affected application, giving full control of the victim's system. Successful exploitation can lead to malware installation, data theft, or further compromise.
Attack surface
Reached remotely over the network via a crafted VML document rendered by Internet Explorer 6.0 or Outlook; no authentication is required, but some user interaction (viewing a malicious page or email) is typically needed. The CVSS vector AV:N/AC:M/Au:N confirms network reachability with medium complexity and no authentication.
Exploitation
Public references include an Exploit tag and a blog noting a zero-day exploit seen in the wild, and EPSS is 0.6144 (99.1st percentile), indicating high likelihood of exploitation. The CVE is not listed in CISA KEV.
What to do
- Apply Microsoft security update MS06-055 (KB925486) to affected Windows XP SP2 systems.
- Disable or unregister vgx.dll where VML rendering is not required.
- Block or filter VML content in email and web traffic until patching is complete.
- Restrict browsing and email clients to trusted sites and disable active content where feasible.
Detection
- Monitor for processes loading vgx.dll and spawning unexpected child processes.
- Inspect network and email traffic for VML files containing rect tags with unusually long fill parameters.
- Review endpoint logs for crashes in Internet Explorer or Outlook related to vgx.dll.
- Hunt for known exploit artifacts referenced in public exploit and vendor advisory sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-4868 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-4868), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.