SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-0002

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation…

HIGH 7.5EPSS 45.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 45.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
45.58% probability · 99th percentile
CISA KEV
Not listed
Affected
microsoft/exchange server · microsoft/office · microsoft/outlook
Source
secure@microsoft.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.