CVE-2006-0027 describes an unspecified vulnerability in Microsoft Exchange Server that allows remote attackers to execute arbitrary code. This high-severity flaw (CVSS 7.5) can be exploited with low complexity via specially crafted vCal or iCal Calendar properties in email messages, leading to potential compromise of confidentiality, integrity, and availability. While not currently on the CISA KEV catalog, a Metasploit module exists for exploitation, indicating readily available exploit code. Despite this, the vulnerability shows minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.