Vulnerability Name:

CVE-2006-4686 (CCN-29210)

Assigned:2006-10-10
Published:2006-10-10
Updated:2018-10-17
Summary:Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2006-4686

Source: CCN
Type: SA22333
Microsoft XML Core Services Information Disclosure and Code Execution

Source: SECUNIA
Type: UNKNOWN
22333

Source: CCN
Type: SECTRACK ID: 1017033
Microsoft XML Core Services Lets Remote Users Execute Arbitrary Code or Obtain Information

Source: SECTRACK
Type: UNKNOWN
1017033

Source: CCN
Type: ASA-2006-217
Windows Security Updates for October 2006 - (MS06-056 - MS06-065)

Source: CCN
Type: US-CERT VU#562788
Microsoft XML Core Services contain a buffer overflow in the XSLT component

Source: CERT-VN
Type: US Government Resource
VU#562788

Source: CCN
Type: Microsoft Security Bulletin MS06-061
Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (924191)

Source: CCN
Type: Microsoft Security Bulletin MS06-071
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (928088)

Source: CCN
Type: Microsoft Security Bulletin MS07-042
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (936227)

Source: OSVDB
Type: UNKNOWN
29426

Source: CCN
Type: OSVDB ID: 29426
Microsoft XML Core Services XSLT Processing Overflow

Source: HP
Type: UNKNOWN
SSRT061264

Source: BID
Type: UNKNOWN
20338

Source: CCN
Type: BID-20338
Microsoft Windows XML Core Services XSLT Buffer Overrun Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2006-3980

Source: MS
Type: UNKNOWN
MS06-061

Source: XF
Type: UNKNOWN
msxml-xlst-bo(29210)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:285

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_core_services:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_core_services:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_parser:2.6:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_core_services:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_core_services:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_parser:2.6:*:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server::x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:-::~~~~itanium~:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server:sp1_itanium:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:285
    V
    XSLT Buffer Overrun Vulnerability
    2008-12-08
    BACK
    microsoft xml core services 3.0
    microsoft xml core services 4.0
    microsoft xml core services 6.0
    microsoft xml parser 2.6
    microsoft xml core services 3.0
    microsoft xml core services 4.0
    microsoft office 2003 sp1
    microsoft office 2003 sp2
    microsoft xml core services 6.0
    microsoft xml parser 2.6
    microsoft windows xp - sp1
    microsoft windows 2000 - sp4
    microsoft windows 2003_server
    microsoft windows xp sp2
    microsoft windows 2003 server -
    microsoft windows 2003_server sp1
    microsoft windows 2003_server sp1_itanium