CVE-2006-6601

Windows Media Player 10.00.00.4036 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-6601. PoCs published by sehato, shinnai.

AI-analyzed exploit summary This script generates a malformed MID file that triggers a denial-of-service condition in Windows Media Player 10. The file contains a minimal MIDI header with an invalid size field, causing the application to crash upon parsing.

Description

Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2) time division fields that are set to 0.

Exploits (2)

exploitdb WORKING POC VERIFIED
by sehato · bashdoswindows
https://www.exploit-db.com/exploits/2935

This script generates a malformed MID file that triggers a denial-of-service condition in Windows Media Player 10. The file contains a minimal MIDI header with an invalid size field, causing the application to crash upon parsing.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Windows Media Player 10.00.00.4036
No auth needed
Prerequisites: Windows XP SP2 with Windows Media Player 10 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by shinnai · textdoswindows
https://www.exploit-db.com/exploits/29285

The provided text describes a denial-of-service vulnerability in multiple applications when processing malicious WMV, MID, or AVI files. It references a BID (Bugtraq ID) and a link to a binary exploit but does not contain actual exploit code.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: Multiple applications (unspecified)
No auth needed
Prerequisites: Victim must open a malicious WMV, MID, or AVI file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/454505/100/0/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/5039
Third Party Advisory mailing-list x_refsource_vim
http://www.attrition.org/pipermail/vim/2006-December/001182.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21612

Scores

EPSS 0.1714
EPSS Percentile 96.7%

Details

CWE
CWE-399
Status published
Products (2)
microsoft/windows_xp
windows/media_player 10.00.00.4036
Published Dec 15, 2006
Tracked Since Feb 18, 2026