First published: Tue Jan 10 2006(Updated: )
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =5.5-sp1 | |
Microsoft Office | =2003-sp1 | |
Microsoft Exchange Server | =5.5-sp4 | |
Microsoft Office | =xp-sp3 | |
Microsoft Outlook | =2000-sp3 | |
Microsoft Outlook | =2003 | |
Microsoft Exchange Server | =5.5-sp2 | |
Microsoft Office | =2003-sp2 | |
Microsoft Outlook | =2002-sp3 | |
Microsoft Exchange Server | =2000-sp3 | |
Microsoft Exchange Server | =5.5-sp3 | |
Microsoft Exchange Server | =5.0-sp1 | |
Microsoft Exchange Server | =5.0-sp2 | |
Microsoft Office | =2000-sp3 | |
Microsoft Exchange Server | =5.5 | |
Microsoft Exchange Server | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0002 has a critical severity level as it allows remote execution of arbitrary code via crafted email messages.
To fix CVE-2006-0002, apply the latest security updates and patches provided by Microsoft for the affected software.
CVE-2006-0002 affects Microsoft Outlook 2000 through 2003, Exchange Server 5.0 SP1 to 5.5 SP4, and other associated Microsoft Office products.
CVE-2006-0002 allows attackers to execute arbitrary code on a user's machine through malicious e-mail messages with specially crafted TNEF MIME attachments.
To mitigate CVE-2006-0002, users should avoid opening suspicious email attachments and ensure their email clients are fully updated.