Vulnerability record · CVE-2006-6251 · published 4 December 2006
CVE-2006-6251: VUPlayer M3U playlist stack buffer overflow enables code execution
Vuplayer · Vuplayer
VUPlayer 2.44 and earlier contains a stack-based buffer overflow triggered by a long string in an M3U playlist file, referred to as an "M3U UNC Name" attack. Opening a crafted playlist can overwrite stack memory and allow arbitrary code execution in the context of the user running the player.
Description
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution with public exploit code and a very high EPSS score, though it requires user interaction and affects a legacy media player.
What it is
VUPlayer 2.44 and earlier contains a stack-based buffer overflow triggered by a long string in an M3U playlist file, referred to as an "M3U UNC Name" attack. Opening a crafted playlist can overwrite stack memory and allow arbitrary code execution in the context of the user running the player.
Impact
An attacker who gets a victim to open a malicious M3U file can execute arbitrary code with the privileges of the VUPlayer process, giving full control of the affected host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
The flaw is reached remotely over the network through a crafted M3U file, requiring no authentication. It does require user interaction, since the victim must open the playlist in VUPlayer.
Exploitation
Public exploit code exists, as indicated by the SecurityFocus Exploit tag and two Exploit-DB entries. The CVE is not listed in CISA KEV, but EPSS is high at roughly 0.68 (99th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Upgrade VUPlayer past 2.44 or remove the product if no fixed version is available, since the record does not name a patched release.
- Block or strip M3U attachments and downloads at email and web gateways where feasible.
- Associate M3U files with a hardened or non-privileged handler and avoid opening playlists from untrusted sources.
- Run VUPlayer with least privilege and apply exploit mitigations such as DEP and ASLR on the host.
Detection
- Monitor for VUPlayer processes spawning child processes or making unexpected network connections after opening a playlist.
- Alert on M3U files containing unusually long lines or UNC-style paths written to disk or opened from email and browser download directories.
- Hunt for crashes or access violations in VUPlayer correlated with recently opened M3U files.
- Review endpoint logs for VUPlayer execution originating from temp or download folders.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-6251 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-6251), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.