PT-2006-1098 · Microsoft · Exchange 5.0 Server+3
John Heasman
+1
·
Published
2006-01-10
·
Updated
2020-04-09
·
CVE-2006-0002
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Outlook versions 2000 through 2003
Microsoft Exchange 5.0 Server version SP2
Microsoft Exchange 5.0 Server version SP4
Microsoft Exchange 2000 version SP3
Microsoft Office (affected versions not specified)
Description:
The issue is related to a remote code execution vulnerability due to improper decoding of Transport Neutral Encapsulation Format (TNEF) MIME attachments in e-mail messages. This allows remote attackers to execute arbitrary code via a crafted attachment. The vulnerability is also related to message length validation.
Recommendations:
For Microsoft Outlook versions 2000 through 2003, consider disabling the handling of TNEF MIME attachments until a fix is available.
For Microsoft Exchange 5.0 Server versions SP2 and SP4, restrict access to TNEF encoded messages to minimize the risk of exploitation.
For Microsoft Exchange 2000 version SP3, avoid processing e-mail messages with crafted TNEF attachments until the issue is resolved.
For Microsoft Office, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exchange 2000
Exchange 5.0 Server
Office
Outlook