← All CVEs

CVE-2006-3445

high · 7.5

Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.

7.5
CVSS
41.0%
EPSS (exploit prob.)
99th
EPSS percentile
2006-11-14
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftwindows_2003_server64-bit
microsoftwindows_2003_serveritanium
microsoftwindows_2003_serverr2
microsoftwindows_2003_serversp1
microsoftwindows_2003_serversp1
microsoftwindows_xpall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-3445