Vulnerability record · CVE-2006-6199 · published 1 December 2006
CVE-2006-6199: BlazeDVD PLF playlist stack buffer overflow allows code execution
Blazevideo · Blaze Dvd
BlazeVideo BlazeDVD Standard and Professional 5.0 (and possibly earlier) contains a stack-based buffer overflow triggered by a long filename in a PLF playlist. Opening a crafted playlist can overwrite stack memory and let an attacker run arbitrary code in the context of the media player. The flaw is remotely reachable and requires no authentication.
Description
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code and a very high EPSS score make exploitation likely, though the flaw is old and requires the user to open a crafted playlist.
What it is
BlazeVideo BlazeDVD Standard and Professional 5.0 (and possibly earlier) contains a stack-based buffer overflow triggered by a long filename in a PLF playlist. Opening a crafted playlist can overwrite stack memory and let an attacker run arbitrary code in the context of the media player. The flaw is remotely reachable and requires no authentication.
Impact
An attacker who gets a victim to open a malicious PLF file can execute arbitrary code with the privileges of the BlazeDVD process, giving full control of the user's session. Failed exploitation would likely crash the player.
Attack surface
Reached by supplying a crafted PLF playlist to BlazeDVD, typically delivered as a file the user opens or a link that launches the player. The network vector (AV:N) and no authentication (Au:N) mean the attacker only needs the victim to load the file; user interaction is implied by opening a playlist but is not explicitly stated in the record.
Exploitation
Not listed in CISA KEV, but EPSS is 0.65276 (99.2nd percentile) and multiple public Exploit-DB entries exist, indicating working exploit code is publicly available. No ransomware use is documented.
What to do
- Upgrade or replace BlazeDVD 5.0 and earlier; check the vendor advisory for a fixed release, since the record does not name one.
- If no patch exists, stop using BlazeDVD for untrusted media and remove or block the PLF file association.
- Block PLF attachments and downloads at email and web gateways, and alert users to the risk of opening playlists from unknown sources.
- Run the player with least privilege and consider application allowlisting or sandboxing to limit code execution impact.
Detection
- Monitor for BlazeDVD process crashes or abnormal child processes spawned from the player.
- Alert on PLF files with unusually long filename fields or oversized playlist entries reaching endpoints.
- Hunt for BlazeDVD launching from email clients, browsers, or download directories with untrusted PLF files.
- Review endpoint telemetry for code execution or shell activity originating from the BlazeDVD process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-6199 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-6199), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.