CVE-2006-3439

EXPLOITED

Microsoft Windows <2003 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2006-3439 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 6 public exploits from researchers including Metasploit, Trirat Puttaraksa, ub3rst4r, including a Metasploit module exploits/windows/smb/ms06_040_netapi.

AI-analyzed exploit summary This is a Metasploit module exploiting a stack buffer overflow in the NetApi32 CanonicalizePathName() function via the NetpwPathCanonicalize RPC call in the Microsoft Server Service. It targets multiple Windows versions and can result in remote code execution or denial of service.

Description

Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16367

This is a Metasploit module exploiting a stack buffer overflow in the NetApi32 CanonicalizePathName() function via the NetpwPathCanonicalize RPC call in the Microsoft Server Service. It targets multiple Windows versions and can result in remote code execution or denial of service.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows Server Service (NetApi32.dll)
Auth required
Prerequisites: Network access to the target · SMB access · Valid credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Trirat Puttaraksa · remotewindows
https://www.exploit-db.com/exploits/2355

This is a functional exploit for CVE-2006-3439 targeting Windows Server 2003 SP0. It leverages a buffer overflow in the Server service via DCERPC to achieve remote code execution by bypassing stack protection via overwriting the security cookie.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows Server 2003 SP0
No auth needed
Prerequisites: Network access to target's SMB port (445/tcp) · Target must be unpatched (pre-MS06-040)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ub3rst4r · cremotewindows
https://www.exploit-db.com/exploits/2265

This is a functional proof-of-concept exploit for CVE-2006-3439, targeting a vulnerability in the Microsoft Server Service. It leverages a buffer overflow in the NetprPathCanonicalize RPC call to achieve remote code execution on vulnerable Windows systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows 2000 SP0-SP4, Windows XP SP0-SP1, Windows NT 4.0
No auth needed
Prerequisites: Network access to the target system · Target system must have the vulnerable Server Service exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Preddy · cremotewindows
https://www.exploit-db.com/exploits/2223

This exploit targets CVE-2006-3439, a buffer overflow in Microsoft Windows' CanonicalizePathName() function. It sends a series of crafted SMB packets to trigger the vulnerability and spawns a reverse shell on port 54321.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows XP SP1 (and potentially Windows 2000)
No auth needed
Prerequisites: Network access to target's SMB port (139) · Target system must be vulnerable (unpatched)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by H D Moore · remotewindows
https://www.exploit-db.com/exploits/2162

This is a Metasploit module exploiting a stack overflow in the NetApi32 NetpIsRemote() function via the NetpwPathCanonicalize RPC call in the Server Service. It targets multiple Windows versions (NT 4.0, 2000, XP SP0/SP1) and achieves remote code execution by leveraging either wcscpy() or stack overflow methods.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows Server Service (NetApi32.dll)
No auth needed
Prerequisites: Network access to target's SMB service (port 445/tcp) · Vulnerable version of Windows (NT 4.0, 2000, XP SP0/SP1)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/smb/ms06_040_netapi.rb

This Metasploit module exploits a stack buffer overflow in the NetApi32 CanonicalizePathName() function via the NetpwPathCanonicalize RPC call in the Server Service, leading to remote code execution on vulnerable Windows systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Unreliable
Target: Microsoft Server Service (NetApi32.dll) on Windows NT 4.0, Windows 2000 SP0-SP4, Windows XP SP0-SP1, and Windows 2003 SP0
No auth needed
Prerequisites: Network access to the target's SMB service · Vulnerable version of the Server Service
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Various Sources x_refsource_misc
http://www.dhs.gov/dhspublic/display?content=5789
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/650769
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016667
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19409
Patch, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-220A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A492
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28002
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3210
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21388

Scores

EPSS 0.8896
EPSS Percentile 99.5%

Details

VulnCheck KEV 2017-06-20
Status published
Products (6)
microsoft/windows_2000
microsoft/windows_2003_server 64-bit
microsoft/windows_2003_server itanium
microsoft/windows_2003_server r2
microsoft/windows_2003_server sp1 (2 CPE variants)
microsoft/windows_xp (3 CPE variants)
Published Aug 09, 2006
Tracked Since Feb 18, 2026