Back

CVE-2006-0002

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.

Published: Jan 10, 2006 Modified: Jun 16, 2026
NVD-CWE-noinfo

CVSS Metrics

Affected Products (16)

Vendor Product Version
microsoft exchange_server 5.0
microsoft exchange_server 5.0
microsoft exchange_server 5.0
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft exchange_server 2000
microsoft office 2000
microsoft office 2003
microsoft office 2003
microsoft office xp
microsoft outlook 2000
microsoft outlook 2002
microsoft outlook 2003

GitHub Security Advisory GHSA-pq9r-2xxh-vvh7

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 45.58%

Top 1% most likely to be exploited

Threat Score 43.7 / 100

Data Sources

NVD EPSS GitHub