← Vulnerability feed

Vulnerability record · CVE-2006-6133 · published 28 November 2006

CVE-2006-6133: Crystal Reports RPT file stack buffer overflow in Visual Studio

Businessobjects · Crystal Reports Xi

A stack-based buffer overflow exists in the Crystal Reports component shipped with Microsoft Visual Studio .NET 2002, 2003, and 2005 (including SP1 releases), formerly Business Objects Crystal Reports XI Professional. Opening a crafted RPT report file can overwrite stack memory and allow arbitrary code execution in the context of the user who opens it.

7.6 CVSS 2.0 High EPSS 52% · top 1.1% CWE-119 · Memory buffer overflow
7.6CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw allows remote code execution with complete impact and has a high EPSS score, though it requires user interaction and a vendor patch has existed since 2007.

What it is

A stack-based buffer overflow exists in the Crystal Reports component shipped with Microsoft Visual Studio .NET 2002, 2003, and 2005 (including SP1 releases), formerly Business Objects Crystal Reports XI Professional. Opening a crafted RPT report file can overwrite stack memory and allow arbitrary code execution in the context of the user who opens it.

Impact

An attacker who gets a victim to open a malicious RPT file can execute arbitrary code with the victim's privileges, giving full control of confidentiality, integrity, and availability on that host.

Attack surface

The flaw is reached remotely by delivering a crafted RPT file, but exploitation requires user interaction because the victim must open the file. No authentication is needed on the target system; the CVSS vector AV:N/AC:H/Au:N reflects network delivery with high attack complexity.

Exploitation

The record shows no CISA KEV listing and no documented ransomware use, but EPSS is high at roughly 0.52 (98.9th percentile), indicating elevated predicted exploitation activity. Reference tags are vendor advisories, a US-CERT alert, and the MS07-052 bulletin, with no public exploit tag supplied.

What to do

  • Apply Microsoft security bulletin MS07-052 (the vendor fix for this Crystal Reports issue) to affected Visual Studio .NET 2002, 2003, and 2005 installations.
  • Treat RPT files from untrusted or external sources as executable content; block or quarantine them at email and web gateways.
  • Restrict which users can open report files and remove or disable the Crystal Reports designer component where it is not required.
  • Run affected report-processing hosts with least privilege so code execution does not inherit administrative rights.

Detection

  • Monitor for Crystal Reports or Visual Studio processes spawning unexpected child processes such as cmd.exe or powershell.exe after an RPT file is opened.
  • Alert on RPT file attachments or downloads arriving from external senders or untrusted sites.
  • Hunt for crashes or abnormal termination of Crystal Reports/Visual Studio processes correlated with recently opened RPT files.
  • Review endpoint logs for suspicious file writes or network connections originating from report-processing applications.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-6133 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-1512Microsoft visual studio .net vulnerabilityStack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP…EPSS 11%9.3CVE-2009-2500Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 24%9.3CVE-2009-2501Microsoft windows 2003 server memory buffer overflow vulnerabilityHeap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Offic…EPSS 27%9.3CVE-2009-2503Microsoft windows 2003 server code injection vulnerabilityGDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office Sys…EPSS 22%9.3CVE-2009-2504Microsoft windows 2003 server vulnerabilityMultiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, W…EPSS 21%9.3CVE-2009-2528Microsoft windows 2003 server code injection vulnerabilityGDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute ar…EPSS 20%9.3CVE-2009-3126Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 23%9.3CVE-2009-2496Microsoft biztalk server memory buffer overflow vulnerabilityHeap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Of…EPSS 29%

Source: NIST National Vulnerability Database (record CVE-2006-6133), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.