← Vulnerability feed

Vulnerability record · CVE-2006-5583 · published 12 December 2006

CVE-2006-5583: Microsoft Windows SNMP Service buffer overflow allows remote code execution

Microsoft · Windows 2003 Server

The SNMP Service in several Microsoft Windows versions contains a buffer overflow that a remote attacker can trigger with a crafted SNMP packet, corrupting memory and potentially executing arbitrary code. Because SNMP is a network-facing service and the flaw is pre-authentication, any reachable host running the affected service is at risk.

10.0 CVSS 2.0 High EPSS 53% · top 1.1%
10.0CVSS 2.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication and yields full code execution, though it affects legacy Windows versions and no confirmed in-the-wild exploitation is recorded.

What it is

The SNMP Service in several Microsoft Windows versions contains a buffer overflow that a remote attacker can trigger with a crafted SNMP packet, corrupting memory and potentially executing arbitrary code. Because SNMP is a network-facing service and the flaw is pre-authentication, any reachable host running the affected service is at risk.

Impact

A successful attacker can execute arbitrary code with the privileges of the SNMP Service, typically SYSTEM, leading to full host compromise.

Attack surface

Reachable over the network via SNMP traffic to the affected service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no reference tags indicate known exploitation, but EPSS is 0.531 (99th percentile), indicating elevated predicted likelihood of exploitation.

What to do

  • Apply Microsoft security bulletin MS06-074 to patch the SNMP Service.
  • Disable the SNMP Service on hosts that do not require it.
  • Restrict UDP 161/162 access to trusted management hosts with firewall rules.
  • Replace SNMPv1/v2c community strings with SNMPv3 where the service must remain enabled.
  • Monitor vendor advisories for updated guidance on affected Windows versions.

Detection

  • Alert on SNMP packets to UDP 161/162 from unexpected or external sources.
  • Monitor for SNMP Service crashes or unexpected service restarts on affected hosts.
  • Review host logs for anomalous child processes spawned by the SNMP Service.
  • Baseline SNMP traffic and flag malformed or unusually large SNMP request payloads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5583 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2015-1701Microsoft Windows Win32k.sys Local Privilege EscalationWin32k.sys in the Windows kernel-mode drivers fails to properly validate input, allowing a local user to elevate privileges by running a crafted appl…KEVEPSS 56%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed10.0CVE-2011-1268Microsoft windows 2003 server improper input validation vulnerabilityThe SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1…EPSS 11%10.0CVE-2011-1868Microsoft windows 2003 server memory buffer overflow vulnerabilityThe Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS res…EPSS 14%10.0CVE-2011-0661Microsoft windows 2003 server improper input validation vulnerabilityThe SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, an…EPSS 45%10.0CVE-2011-0654Windows CIFS browser service integer underflow leads to heap overflowAn integer underflow in the BowserWriteErrorLogEntry function of the CIFS browser service (Mrxsmb.sys/bowser.sys) in multiple Windows versions causes…EPSS 68%analysed

Source: NIST National Vulnerability Database (record CVE-2006-5583), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.