CVE-2006-3670

winlpd < 1.26 - Remote Code Execution via Long String to TCP Port 515

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3670. PoCs published by Pablo Isola.

AI-analyzed exploit summary This is a remote buffer overflow exploit for Winlpd 1.2 Build 1076, leveraging a crafted payload to achieve remote code execution via a TCP connection to port 515. The exploit includes shellcode and a return address for Windows 2K and XP.

Description

Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a request to TCP port 515.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Pablo Isola · perlremotewindows
https://www.exploit-db.com/exploits/2014

This is a remote buffer overflow exploit for Winlpd 1.2 Build 1076, leveraging a crafted payload to achieve remote code execution via a TCP connection to port 515. The exploit includes shellcode and a return address for Windows 2K and XP.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winlpd 1.2 Build 1076
No auth needed
Prerequisites: Network access to the target on port 515 · Vulnerable version of Winlpd running
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2823
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/displayvuln.php?osvdb_id=27332
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441302/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27759
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2014
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21058
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19011
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016510

Scores

EPSS 0.0730
EPSS Percentile 93.6%

Details

Status published
Products (1)
rabox/winlpd < 1.26
Published Jul 18, 2006
Tracked Since Feb 18, 2026