CVE-2006-4868: Buffer Overflow
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4868?
CVE-2006-4868 is considered critical due to the potential for remote code execution via specially crafted VML files.
How do I fix CVE-2006-4868?
To mitigate CVE-2006-4868, users should apply the latest security patches from Microsoft for affected versions of Windows and software.
Which Microsoft products are affected by CVE-2006-4868?
CVE-2006-4868 affects Microsoft Internet Explorer 6.0 and Microsoft Outlook 2003 primarily on Windows XP SP2.
Can CVE-2006-4868 be exploited remotely?
Yes, CVE-2006-4868 can be exploited remotely by submitting a malicious VML file to the target system.
What type of vulnerability is CVE-2006-4868?
CVE-2006-4868 is a stack-based buffer overflow vulnerability in the Vector Graphics Rendering engine.