Vulnerability record · CVE-2006-5745 · published 6 November 2006
CVE-2006-5745: Microsoft XML Core Services XMLHTTP ActiveX memory corruption
Microsoft · Xml Core Services
The setRequestHeader method in the XMLHTTP ActiveX Control 4.0 shipped with Microsoft XML Core Services 4.0 on Windows contains a memory corruption flaw when reached through Internet Explorer. Crafted arguments to setRequestHeader can corrupt memory and allow remote code execution. The record notes some details come from third-party information and does not specify affected version ranges beyond MSXML 4.0.
Description
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with full impact and public exploit material, though the high access complexity and required user interaction temper the rating.
What it is
The setRequestHeader method in the XMLHTTP ActiveX Control 4.0 shipped with Microsoft XML Core Services 4.0 on Windows contains a memory corruption flaw when reached through Internet Explorer. Crafted arguments to setRequestHeader can corrupt memory and allow remote code execution. The record notes some details come from third-party information and does not specify affected version ranges beyond MSXML 4.0.
Impact
An attacker who successfully triggers the flaw can execute arbitrary code in the context of the user running Internet Explorer. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.
Attack surface
Reached remotely over the network when a user views attacker-controlled content in Internet Explorer that instantiates the XMLHTTP ActiveX control; no authentication is required, but the vector shows high access complexity and the description implies user interaction with the page.
Exploitation
Not listed in CISA KEV, but EPSS is 0.7609 (99.5th percentile) and a SecurityFocus reference carries an Exploit tag, with an Exploit-DB entry also present, indicating public exploit material exists.
What to do
- Apply Microsoft security bulletin MS06-071, which addresses this XMLHTTP ActiveX issue, and confirm the patched MSXML 4.0 build is installed.
- Disable or kill-bit the vulnerable XMLHTTP ActiveX control where it is not required for business use.
- Restrict Internet Explorer use of ActiveX controls and enforce consistent zone and ActiveX settings across the estate.
- Where feasible, migrate users off Internet Explorer and legacy MSXML 4.0 dependencies to supported browsers and XML libraries.
Detection
- Hunt for Internet Explorer processes loading msxml4.dll or instantiating the XMLHTTP ActiveX control, especially from untrusted or web-origin content.
- Monitor for crashes or memory corruption indicators in iexplore.exe tied to MSXML/XMLHTTP activity.
- Review proxy and web logs for known exploit hosts or payload delivery tied to this CVE, and alert on Exploit-DB or SecurityFocus signatures.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5745 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5745), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.