CVE-2006-3440

Microsoft Windows 2000 SP4, XP SP1-SP2, Server 2003 SP1 - Remote Code Execution via Winsock Hostname Handling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3440.

AI-analyzed exploit summary This Python script implements a malicious DNS server that exploits CVE-2006-3440 by sending a crafted DNS response with a malformed TXT record, causing a denial-of-service (DoS) in Microsoft Windows DNS services (services.exe crash). The exploit requires the target to use the attacker's DNS server.

Description

Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."

Exploits (1)

exploitdb WORKING POC
pythondoswindows
https://www.exploit-db.com/exploits/2900

This Python script implements a malicious DNS server that exploits CVE-2006-3440 by sending a crafted DNS response with a malformed TXT record, causing a denial-of-service (DoS) in Microsoft Windows DNS services (services.exe crash). The exploit requires the target to use the attacker's DNS server.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows DNS Server (Windows 2000 SP0, SP1, and potentially SP4)
No auth needed
Prerequisites: Target must use the attacker's DNS server for resolution · Victim must query a crafted hostname
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016653
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3211
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A747
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19319
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21394
Patch, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-220A.html
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/908276

Scores

EPSS 0.7364
EPSS Percentile 98.8%

Details

Status published
Products (4)
microsoft/windows_2000
microsoft/windows_2003_server 64-bit
microsoft/windows_2003_server sp1 (2 CPE variants)
microsoft/windows_xp (3 CPE variants)
Published Aug 09, 2006
Tracked Since Feb 18, 2026