CVE-2006-0027
Microsoft Exchange - RCE
Title source: llmDescription
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
Exploits (1)
metasploit
WORKING POC
by pusscat · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/smtp/ms06_019_exchange.rb
References (12)
Scores
EPSS
0.7219
EPSS Percentile
98.8%
Details
Status
published
Products (2)
microsoft/exchange_server
2000 sp3
microsoft/exchange_server
2003 sp1 (2 CPE variants)
Published
May 10, 2006
Tracked Since
Feb 18, 2026