CVE-2006-0002: High severity Microsoft Exchange Server vulnerability
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0002?
CVE-2006-0002 has a critical severity level as it allows remote execution of arbitrary code via crafted email messages.
How do I fix CVE-2006-0002?
To fix CVE-2006-0002, apply the latest security updates and patches provided by Microsoft for the affected software.
Which products are affected by CVE-2006-0002?
CVE-2006-0002 affects Microsoft Outlook 2000 through 2003, Exchange Server 5.0 SP1 to 5.5 SP4, and other associated Microsoft Office products.
What type of attack does CVE-2006-0002 allow?
CVE-2006-0002 allows attackers to execute arbitrary code on a user's machine through malicious e-mail messages with specially crafted TNEF MIME attachments.
What are the recommended mitigations for CVE-2006-0002?
To mitigate CVE-2006-0002, users should avoid opening suspicious email attachments and ensure their email clients are fully updated.