Executive Summary

Informations
Name MS06-003 First vendor Publication N/A
Vendor Microsoft Last vendor Modification N/A
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Vulnerability in TNEF Decoding in Microsoft Outlook and Microsoft Exchange Could Allow Remote Code Execution (902412)

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:1082
 
Oval ID: oval:org.mitre.oval:def:1082
Title: Exchange 2000 Server TNEF Decoding Vulnerability
Description: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Family: windows Class: vulnerability
Reference(s): CVE-2006-0002
Version: 1
Platform(s): Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Product(s): Microsoft Outlook
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:1165
 
Oval ID: oval:org.mitre.oval:def:1165
Title: Outlook 2002 TNEF Decoding Vulnerability
Description: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Family: windows Class: vulnerability
Reference(s): CVE-2006-0002
Version: 10
Platform(s): Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Product(s): Microsoft Outlook
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:1316
 
Oval ID: oval:org.mitre.oval:def:1316
Title: Exchange Server 5.0 TNEF Decoding Vulnerability
Description: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Family: windows Class: vulnerability
Reference(s): CVE-2006-0002
Version: 1
Platform(s): Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Product(s): Microsoft Outlook
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:1456
 
Oval ID: oval:org.mitre.oval:def:1456
Title: Outlook 2003 TNEF Decoding Vulnerability
Description: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Family: windows Class: vulnerability
Reference(s): CVE-2006-0002
Version: 9
Platform(s): Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Product(s): Microsoft Outlook
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:1485
 
Oval ID: oval:org.mitre.oval:def:1485
Title: Outlook 2000 TNEF Decoding Vulnerability
Description: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Family: windows Class: vulnerability
Reference(s): CVE-2006-0002
Version: 8
Platform(s): Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Product(s): Microsoft Outlook
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:624
 
Oval ID: oval:org.mitre.oval:def:624
Title: Exchange Server 5.5 TNEF Decoding Vulnerability
Description: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Family: windows Class: vulnerability
Reference(s): CVE-2006-0002
Version: 2
Platform(s): Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Product(s): Microsoft Outlook
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 9
Application 4
Application 3

Open Source Vulnerability Database (OSVDB)

Id Description
22305 Microsoft Outlook/Exchange TNEF Decoding Arbitrary Code Execution

Microsoft Outlook and Exchange contain a flaw that may allow arbitrary code execution. The issue is due to the servers not properly sanitizing input via e-mail messages. By sending an e-mail with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, a user who views (opens or previews) the e-mail will execute custom code sent by an attacker.

Information Assurance Vulnerability Management (IAVM)

Date Description
2006-01-12 IAVM : 2006-A-0003 - Microsoft Outlook and Exchange TNEF Decoding Vulnerability
Severity : Category I - VMSKEY : V0011719

Snort® IPS/IDS

Date Description
2014-01-10 Microsoft Windows Exchange and Outlook TNEF Decoding Integer Overflow attempt
RuleID : 17481 - Revision : 14 - Type : SERVER-MAIL

Nessus® Vulnerability Scanner

Date Description
2006-01-10 Name : Arbitrary code can be executed on the remote host through the email client or...
File : smb_nt_ms06-003.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-17 11:45:18
  • Multiple Updates
2013-11-11 12:41:04
  • Multiple Updates