CVE-2006-0002
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 45.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 45.58% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/exchange server · microsoft/office · microsoft/outlook
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/18368Patch, Third Party Advisory
- http://securityreason.com/securityalert/330Third Party Advisory
- http://securityreason.com/securityalert/331Third Party Advisory
- http://securitytracker.com/id?1015460Patch, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1015461Patch, Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-004.htmThird Party Advisory
- http://www.kb.cert.org/vuls/id/252146Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/421518/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/421520/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/16197Patch, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA06-010A.htmlPatch, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/0119Permissions Required
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-003Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22878Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1082Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1165Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1316Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1456Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1485Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A624Third Party Advisory
- http://secunia.com/advisories/18368Patch, Third Party Advisory
- http://securityreason.com/securityalert/330Third Party Advisory
- http://securityreason.com/securityalert/331Third Party Advisory
- http://securitytracker.com/id?1015460Patch, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1015461Patch, Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-004.htmThird Party Advisory
- http://www.kb.cert.org/vuls/id/252146Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/421518/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/421520/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/16197Patch, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.