CVE-2006-0002

Microsoft Exchange Server and Outlook - Remote Code Execution via TNEF MIME Attachment

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.

References (20)

Core 20
Core References
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm
Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015460
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/421520/100/0/threaded
Third Party Advisory vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A624
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22878
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/331
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0119
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-003
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/330
Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16197
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/421518/100/0/threaded
Patch, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18368
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/252146
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-010A.html
Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015461

Scores

EPSS 0.4558
EPSS Percentile 98.7%

Details

Status published
Products (9)
microsoft/exchange_server 5.0 (3 CPE variants)
microsoft/exchange_server 5.5 (5 CPE variants)
microsoft/exchange_server 2000 sp3
microsoft/office 2000 sp3
microsoft/office 2003 sp1 (2 CPE variants)
microsoft/office xp sp3
microsoft/outlook 2000 sp3
microsoft/outlook 2002 sp3
microsoft/outlook 2003
Published Jan 10, 2006
Tracked Since Feb 18, 2026