CVE-2006-1043

Microsoft Visual Studio and Visual InterDev - Stack-based Buffer Overflow via Long DataProject Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1043. PoCs published by Kozan.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in Microsoft Visual Studio 6.0 SP6 by crafting a malformed .dbp file. It includes shellcode to execute calc.exe and leverages a JMP ESP instruction from VSSLN.DLL to redirect execution flow.

Description

Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Solution (.sln).

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kozan · clocalwindows
https://www.exploit-db.com/exploits/1555

This exploit demonstrates a buffer overflow vulnerability in Microsoft Visual Studio 6.0 SP6 by crafting a malformed .dbp file. It includes shellcode to execute calc.exe and leverages a JMP ESP instruction from VSSLN.DLL to redirect execution flow.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Visual Studio 6.0 SP6
No auth needed
Prerequisites: Victim must open the malformed .dbp file in Microsoft Visual Studio 6.0 SP6
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015721
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23711
Exploit, Vendor Advisory x_refsource_misc
http://www.frsirt.com/exploits/20060305.ms-visual-dbp.c.php
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19081
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0825
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16953
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/426767/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/426830/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25148

Scores

EPSS 0.2240
EPSS Percentile 97.4%

Details

CWE
CWE-119
Status published
Products (2)
microsoft/visual_interdev 6.0
microsoft/visual_studio 6.0 (6 CPE variants)
Published Mar 07, 2006
Tracked Since Feb 18, 2026