CVE-2006-5745

EXPLOITED

Microsoft XML Core Services 4.0 - RCE

Title source: llm

Description

Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.

Exploits (5)

exploitdb WORKING POC VERIFIED
by ~Fyodor · htmlremotewindows
https://www.exploit-db.com/exploits/2749
exploitdb WORKING POC VERIFIED
by anonymous · htmlremotewindows
https://www.exploit-db.com/exploits/2743
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16532
exploitdb WORKING POC VERIFIED
by M03 · cremotewindows
https://www.exploit-db.com/exploits/2753
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms06_071_xml_core.rb

Scores

EPSS 0.8741
EPSS Percentile 99.4%

Exploitation Intel

VulnCheck KEV 2006-11-14

Classification

Status draft

Affected Products (1)

microsoft/xml_core_services

Timeline

Published Nov 06, 2006
Tracked Since Feb 18, 2026