CVE-2006-4692

Microsoft Windows XP <SP2 - Command Injection

Title source: llm

Description

Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."

Scores

EPSS 0.6664
EPSS Percentile 98.5%

Classification

CWE
CWE-88
Status draft

Affected Products (4)

microsoft/windows_server_2003
microsoft/windows_server_2003
microsoft/windows_xp
microsoft/windows_xp

Timeline

Published Oct 10, 2006
Tracked Since Feb 18, 2026