Vulnerability record · CVE-2006-6063 · published 22 November 2006
CVE-2006-6063: XMPlay M3U playlist stack buffer overflow allows remote code execution
Un4seen · Xmplay
Un4seen XMPlay 3.3.0.5 and earlier contains a stack-based buffer overflow triggered by a long FileName field in an M3U playlist file. A long DisplayName field causes a crash. Because the flaw is reachable from a remotely supplied playlist, it can lead to arbitrary code execution on the victim's machine.
Description
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code exists and EPSS is very high, but exploitation requires the user to open a crafted playlist, which limits mass exploitation.
What it is
Un4seen XMPlay 3.3.0.5 and earlier contains a stack-based buffer overflow triggered by a long FileName field in an M3U playlist file. A long DisplayName field causes a crash. Because the flaw is reachable from a remotely supplied playlist, it can lead to arbitrary code execution on the victim's machine.
Impact
An attacker who gets a crafted M3U file opened can execute arbitrary code in the context of the XMPlay process, or at minimum crash it. This gives full control of the affected user's session if code execution succeeds.
Attack surface
Reached by opening a malicious M3U playlist, typically delivered by download, email or a web link. No authentication is required; the only precondition is that the user opens the file, so limited user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.583 (99th percentile) and a public Exploit-DB entry (2815) exists, indicating exploit code is publicly available and exploitation is plausible.
What to do
- Upgrade XMPlay to a version later than 3.3.0.5, or apply the vendor fix referenced in the Secunia advisory.
- If upgrade is not possible, block or restrict opening of untrusted M3U files and remove the M3U file association from XMPlay.
- Filter inbound email and web downloads for M3U attachments and enforce content-type checks at the gateway.
- Run XMPlay with least privilege and consider application allowlisting to limit the impact of code execution.
Detection
- Monitor for XMPlay process crashes or abnormal child processes spawned from xmplay.exe.
- Inspect M3U files for oversized FileName or DisplayName fields before they reach endpoints.
- Alert on email or web download events involving .m3u files from untrusted sources.
- Review endpoint logs for code execution originating from the XMPlay process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-6063 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2006-6063), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.