CVE-2006-0027: High severity Microsoft Exchange Server vulnerability
Published May 10, 2006
·Updated
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
Affected Software
3 affected components
Microsoft Exchange Server=2000-sp3
Microsoft Exchange Server=2003-sp1
Microsoft Exchange Server=2003-sp2
Remediation
Patch Available
Patch Available
Event History
May 10, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0027?
CVE-2006-0027 is classified as a critical vulnerability allowing remote code execution.
2
How do I fix CVE-2006-0027?
To fix CVE-2006-0027, apply the latest security patches provided by Microsoft for affected versions of Exchange Server.
3
What software versions are affected by CVE-2006-0027?
CVE-2006-0027 affects Microsoft Exchange Server 2000 SP3 and Microsoft Exchange Server 2003 SP1 and SP2.
4
What type of attack is associated with CVE-2006-0027?
CVE-2006-0027 is associated with remote attacks exploiting crafted vCal or iCal Calendar properties in email messages.
5
Can CVE-2006-0027 be exploited without user interaction?
Yes, CVE-2006-0027 can be exploited remotely without requiring user interaction.