Vulnerability record · CVE-2006-5583 · published 12 December 2006
CVE-2006-5583: Microsoft Windows SNMP Service buffer overflow allows remote code execution
Microsoft · Windows 2003 Server
The SNMP Service in several Microsoft Windows versions contains a buffer overflow that a remote attacker can trigger with a crafted SNMP packet, corrupting memory and potentially executing arbitrary code. Because SNMP is a network-facing service and the flaw is pre-authentication, any reachable host running the affected service is at risk.
Description
Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and yields full code execution, though it affects legacy Windows versions and no confirmed in-the-wild exploitation is recorded.
What it is
The SNMP Service in several Microsoft Windows versions contains a buffer overflow that a remote attacker can trigger with a crafted SNMP packet, corrupting memory and potentially executing arbitrary code. Because SNMP is a network-facing service and the flaw is pre-authentication, any reachable host running the affected service is at risk.
Impact
A successful attacker can execute arbitrary code with the privileges of the SNMP Service, typically SYSTEM, leading to full host compromise.
Attack surface
Reachable over the network via SNMP traffic to the affected service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no reference tags indicate known exploitation, but EPSS is 0.531 (99th percentile), indicating elevated predicted likelihood of exploitation.
What to do
- Apply Microsoft security bulletin MS06-074 to patch the SNMP Service.
- Disable the SNMP Service on hosts that do not require it.
- Restrict UDP 161/162 access to trusted management hosts with firewall rules.
- Replace SNMPv1/v2c community strings with SNMPv3 where the service must remain enabled.
- Monitor vendor advisories for updated guidance on affected Windows versions.
Detection
- Alert on SNMP packets to UDP 161/162 from unexpected or external sources.
- Monitor for SNMP Service crashes or unexpected service restarts on affected hosts.
- Review host logs for anomalous child processes spawned by the SNMP Service.
- Baseline SNMP traffic and flag malformed or unusually large SNMP request payloads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5583 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5583), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.