PT-2006-1098 · Microsoft · Exchange 5.0 Server+3

John Heasman

+1

·

Published

2006-01-10

·

Updated

2020-04-09

·

CVE-2006-0002

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Outlook versions 2000 through 2003 Microsoft Exchange 5.0 Server version SP2 Microsoft Exchange 5.0 Server version SP4 Microsoft Exchange 2000 version SP3 Microsoft Office (affected versions not specified)
Description: The issue is related to a remote code execution vulnerability due to improper decoding of Transport Neutral Encapsulation Format (TNEF) MIME attachments in e-mail messages. This allows remote attackers to execute arbitrary code via a crafted attachment. The vulnerability is also related to message length validation.
Recommendations: For Microsoft Outlook versions 2000 through 2003, consider disabling the handling of TNEF MIME attachments until a fix is available. For Microsoft Exchange 5.0 Server versions SP2 and SP4, restrict access to TNEF encoded messages to minimize the risk of exploitation. For Microsoft Exchange 2000 version SP3, avoid processing e-mail messages with crafted TNEF attachments until the issue is resolved. For Microsoft Office, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0002

Affected Products

Exchange 2000
Exchange 5.0 Server
Office
Outlook