Vulnerabilities > CVE-2006-0027 - Unspecified vulnerability in Microsoft Exchange Server 2000/2003
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Metasploit
description | This module triggers a heap overflow vulnerability in MS Exchange that occurs when multiple malformed MODPROP values occur in a VCAL request. |
id | MSF:AUXILIARY/DOS/WINDOWS/SMTP/MS06_019_EXCHANGE |
last seen | 2020-01-13 |
modified | 2017-07-24 |
published | 2007-05-01 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0027 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/dos/windows/smtp/ms06_019_exchange.rb |
title | MS06-019 Exchange MODPROP Heap Overflow |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-019.NASL |
description | The remote host is running a version of Exchange that is vulnerable to a bug in the vCal or iCal attachment handling routine that could allow an attacker execute arbitrary code on the remote host by sending a specially crafted email. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21332 |
published | 2006-05-09 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21332 |
title | MS06-019: Vulnerability in Microsoft Exchange Could Allow Remote Code Execution (916803) |
code |
|
Oval
accepted 2008-05-05T04:00:14.118-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Jeff Cheng organization Opsware, Inc. name Clifford Farrugia organization GFI Software
description Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties. family windows id oval:org.mitre.oval:def:1818 status accepted submitted 2006-05-10T03:16:00.000-04:00 title Exchange 2000,SP4 Calendar Vulnerability version 7 accepted 2008-05-05T04:00:15.037-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Jeff Cheng organization Opsware, Inc. name Clifford Farrugia organization GFI Software
description Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties. family windows id oval:org.mitre.oval:def:1996 status accepted submitted 2006-05-10T03:16:00.000-04:00 title Exchange 2003,SP2 Calendar Vulnerability version 7 accepted 2008-05-05T04:00:16.084-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Jeff Cheng organization Opsware, Inc. name Clifford Farrugia organization GFI Software
description Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties. family windows id oval:org.mitre.oval:def:2035 status accepted submitted 2006-05-10T03:16:00.000-04:00 title Exchange 2003,SP1 Calendar Vulnerability version 7
References
- http://www.us-cert.gov/cas/techalerts/TA06-129A.html
- http://www.kb.cert.org/vuls/id/303452
- http://www.securityfocus.com/bid/17908
- http://www.osvdb.org/25338
- http://securitytracker.com/id?1016048
- http://secunia.com/advisories/20029
- http://www.vupen.com/english/advisories/2006/1743
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25556
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2035
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1996
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1818
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-019