Vulnerability record · CVE-2006-0002 · published 10 January 2006
CVE-2006-0002: Microsoft Outlook and Exchange TNEF message length validation remote code execution
Microsoft · Exchange Server
Microsoft Outlook 2000 through 2003, Exchange 5.0 SP2, 5.5 SP4, Exchange 2000 SP3, and Office contain an unspecified vulnerability related to message length validation when processing a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment. A remote attacker can deliver a specially crafted email message that leads to arbitrary code execution. The flaw is serious because email is a routine, trusted channel and no user interaction beyond receiving or opening the message may be required.
Description
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution through email with a high EPSS score and available patches, though no confirmed in-the-wild exploitation is documented.
What it is
Microsoft Outlook 2000 through 2003, Exchange 5.0 SP2, 5.5 SP4, Exchange 2000 SP3, and Office contain an unspecified vulnerability related to message length validation when processing a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment. A remote attacker can deliver a specially crafted email message that leads to arbitrary code execution. The flaw is serious because email is a routine, trusted channel and no user interaction beyond receiving or opening the message may be required.
Impact
An attacker can execute arbitrary code in the context of the affected client or server process, giving full control of the victim host or Exchange server. This can lead to data theft, further compromise of the mail environment, and use of the host as a foothold.
Attack surface
Reached remotely over the network by sending an email containing a crafted TNEF MIME attachment to a vulnerable Outlook client or Exchange server. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required; the record does not state whether opening the message is necessary, so user interaction cannot be confirmed from the supplied data.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is 0.45584 (98.7th percentile), indicating a high modeled likelihood of exploitation, and multiple references carry Patch tags, but no reference confirms active exploitation.
What to do
- Apply the Microsoft security update for MS06-003 (referenced as a vendor patch) to Outlook, Exchange, and Office installations.
- Block or strip TNEF (winmail.dat) attachments at the mail gateway where business needs allow.
- Retire or isolate end-of-life Outlook 2000-2003 and Exchange 5.0/5.5/2000 systems that cannot be patched.
- Restrict Exchange server exposure and apply least privilege to mail service accounts to limit post-exploitation impact.
Detection
- Monitor mail gateway and Exchange logs for inbound messages with TNEF/winmail.dat attachments, especially unusual sizes or malformed MIME structure.
- Hunt for unexpected child processes spawned by Outlook or Exchange processes (for example, cmd.exe, powershell.exe, or scripting hosts).
- Review endpoint telemetry for crashes or memory corruption events in Outlook or Exchange components following email delivery.
- Correlate mail delivery records with subsequent suspicious process or network activity on client and server hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0002 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0002), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.