Vulnerability record · CVE-2006-5650 · published 7 November 2006
CVE-2006-5650: ICQ ActiveX control allows remote code execution via DownloadAgent
Aol · Icq
The ICQPhone.SipxPhoneManager ActiveX control shipped with America Online ICQ 5.1 exposes a DownloadAgent function that downloads and executes arbitrary code. Because the control is reachable from a web page, an attacker can trigger code execution on a victim's machine, for example by luring them with an ICQ avatar. This is a remote, unauthenticated code execution flaw in a widely deployed consumer client.
Description
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a high EPSS score, but the record lacks confirmed in-the-wild exploitation and the affected product is a legacy 2006 client.
What it is
The ICQPhone.SipxPhoneManager ActiveX control shipped with America Online ICQ 5.1 exposes a DownloadAgent function that downloads and executes arbitrary code. Because the control is reachable from a web page, an attacker can trigger code execution on a victim's machine, for example by luring them with an ICQ avatar. This is a remote, unauthenticated code execution flaw in a widely deployed consumer client.
Impact
An attacker gains arbitrary code execution in the context of the logged-in user, allowing installation of malware, credential theft or full host compromise. No privilege escalation is needed beyond the user's own rights.
Attack surface
Reached over the network through the vulnerable ActiveX control, typically by a victim visiting a malicious or compromised web page that instantiates it. No authentication is required; some user interaction (visiting the page or viewing the crafted avatar) is implied by the vector and description.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, though EPSS is high at 0.666 (99.3rd percentile), indicating elevated predicted exploitation likelihood. Reference tags are advisory-only, so no confirmed in-the-wild exploitation is documented here.
What to do
- Apply the vendor fix or upgrade ICQ to a version that removes or repairs the ICQPhone.SipxPhoneManager control; if no patch exists, uninstall ICQ 5.1.
- Set the kill bit for the affected ActiveX CLSID to block instantiation in Internet Explorer.
- Restrict or disable ActiveX execution in browsers and enforce allow-listing of controls.
- Block outbound downloads and execution from untrusted sources at the endpoint and network layers.
- Retire the legacy ICQ 5.1 client from managed endpoints in favour of a supported messaging platform.
Detection
- Monitor for processes spawned by browser or ICQ processes that write and execute files from temporary or user profile directories.
- Audit registry and browser logs for instantiation of the ICQPhone.SipxPhoneManager ActiveX control.
- Alert on network fetches of executable payloads initiated by ICQ or browser processes.
- Hunt for unexpected persistence or new binaries appearing shortly after ICQ or browser activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5650 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5650), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.