CVE-2006-5583
Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 53.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 53.10% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2003 server
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/23307
- http://securitytracker.com/id?1017371
- http://www.kb.cert.org/vuls/id/901584US Government Resource
- http://www.securityfocus.com/archive/1/454969/100/200/threaded
- http://www.securityfocus.com/bid/21537
- http://www.us-cert.gov/cas/techalerts/TA06-346A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/4967
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-074
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1047
- http://secunia.com/advisories/23307
- http://securitytracker.com/id?1017371
- http://www.kb.cert.org/vuls/id/901584US Government Resource
- http://www.securityfocus.com/archive/1/454969/100/200/threaded
- http://www.securityfocus.com/bid/21537
- http://www.us-cert.gov/cas/techalerts/TA06-346A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/4967
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-074
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1047
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.