← Vulnerability feed

Vulnerability record · CVE-2006-5650 · published 7 November 2006

CVE-2006-5650: ICQ ActiveX control allows remote code execution via DownloadAgent

Aol · Icq

The ICQPhone.SipxPhoneManager ActiveX control shipped with America Online ICQ 5.1 exposes a DownloadAgent function that downloads and executes arbitrary code. Because the control is reachable from a web page, an attacker can trigger code execution on a victim's machine, for example by luring them with an ICQ avatar. This is a remote, unauthenticated code execution flaw in a widely deployed consumer client.

7.5 CVSS 2.0 High EPSS 67% · top 0.7%
7.5CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with a high EPSS score, but the record lacks confirmed in-the-wild exploitation and the affected product is a legacy 2006 client.

What it is

The ICQPhone.SipxPhoneManager ActiveX control shipped with America Online ICQ 5.1 exposes a DownloadAgent function that downloads and executes arbitrary code. Because the control is reachable from a web page, an attacker can trigger code execution on a victim's machine, for example by luring them with an ICQ avatar. This is a remote, unauthenticated code execution flaw in a widely deployed consumer client.

Impact

An attacker gains arbitrary code execution in the context of the logged-in user, allowing installation of malware, credential theft or full host compromise. No privilege escalation is needed beyond the user's own rights.

Attack surface

Reached over the network through the vulnerable ActiveX control, typically by a victim visiting a malicious or compromised web page that instantiates it. No authentication is required; some user interaction (visiting the page or viewing the crafted avatar) is implied by the vector and description.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, though EPSS is high at 0.666 (99.3rd percentile), indicating elevated predicted exploitation likelihood. Reference tags are advisory-only, so no confirmed in-the-wild exploitation is documented here.

What to do

  • Apply the vendor fix or upgrade ICQ to a version that removes or repairs the ICQPhone.SipxPhoneManager control; if no patch exists, uninstall ICQ 5.1.
  • Set the kill bit for the affected ActiveX CLSID to block instantiation in Internet Explorer.
  • Restrict or disable ActiveX execution in browsers and enforce allow-listing of controls.
  • Block outbound downloads and execution from untrusted sources at the endpoint and network layers.
  • Retire the legacy ICQ 5.1 client from managed endpoints in favour of a supported messaging platform.

Detection

  • Monitor for processes spawned by browser or ICQ processes that write and execute files from temporary or user profile directories.
  • Audit registry and browser logs for instantiation of the ICQPhone.SipxPhoneManager ActiveX control.
  • Alert on network fetches of executable payloads initiated by ICQ or browser processes.
  • Hunt for unexpected persistence or new binaries appearing shortly after ICQ or browser activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5650 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-5650), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.