{"vuid":"VU#303452","idnumber":"303452","name":"Microsoft Exchange fails to properly handle vCal and iCal properties","keywords":["Microsoft","Exchange Server","remote code execution","ms06-may","MS06-019"],"overview":"Microsoft Exchange Server does not properly handle the vCal and iCal properties of email messages. Exploitation of this vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on an Exchange Server.","clean_desc":"Microsoft Exchange Server Microsoft's Exchange Server supports a number of protocols for handling email, including the Simple Mail Transfer Protocol (SMTP) and SMTP extended verbs as defined by RFC 2821. vCal and iCal Properties According to Microsoft, Virtual Calendar (vCAL) and Internet Calendar (iCAL) are MIME content types used by Microsoft Exchange Server and email clients when sending and exchanging information related to calendars and scheduling. Microsoft Collaboration Data Objects (CDO) for Exchange Microsoft CDO is a scripting library used to develop applications that handle email. Microsoft CDO for Exchange is commonly associated with Exchange Collaboration Data Objects (EXCDO) and Collaboration Data Objects for Exchange (CDOEX). Microsoft CDO for Exchange is used to process iCal and vCal data in email messages. The Problem Microsoft CDO for Exchange does not  properly handle the iCal or vCal properties of email messages. If a remote attacker sends an Exchange Server an email containing specially crafted iCal or vCal properties, that attacker may be able to corrupt the server in a way that enables the attacker to execute arbitrary code. More information is available in Microsoft Security Bulletin MS06-019.","impact":"A remote, unauthenticated attacker may be able execute arbitrary code on a vulnerable system.","resolution":"Apply an update \nMicrosoft has addressed this issue in Microsoft Security Bulletin MS06-019.","workarounds":"Refer to Microsoft Security Bulletin MS06-019 for workarounds for this issue.","sysaffected":"","thanks":"This vulnerability was reported in Microsoft Security Bulletin \nMS06-019","author":"This document was written by Jeff Gennari based on information provided by Microsoft.","public":["http://www.microsoft.com/technet/security/bulletin/ms06-019.mspx","http://support.microsoft.com/kb/912918","http://xforce.iss.net/xforce/alerts/id/221","http://secunia.com/advisories/20029/"],"cveids":["CVE-2006-0027"],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2006-05-09T17:34:49Z","publicdate":"2006-05-09T00:00:00Z","datefirstpublished":"2006-05-09T18:11:42Z","dateupdated":"2006-06-22T16:22:58Z","revision":43,"vrda_d1_directreport":"0","vrda_d1_population":"4","vrda_d1_impact":"4","cam_widelyknown":"15","cam_exploitation":"0","cam_internetinfrastructure":"7","cam_population":"15","cam_impact":"18","cam_easeofexploitation":"10","cam_attackeraccessrequired":"20","cam_scorecurrent":"22.275","cam_scorecurrentwidelyknown":"27.3375","cam_scorecurrentwidelyknownexploited":"47.5875","ipprotocol":"","cvss_accessvector":"","cvss_accesscomplexity":"","cvss_authentication":null,"cvss_confidentialityimpact":"","cvss_integrityimpact":"","cvss_availabilityimpact":"","cvss_exploitablity":null,"cvss_remediationlevel":"","cvss_reportconfidence":"","cvss_collateraldamagepotential":"","cvss_targetdistribution":"","cvss_securityrequirementscr":"","cvss_securityrequirementsir":"","cvss_securityrequirementsar":"","cvss_basescore":"","cvss_basevector":"","cvss_temporalscore":"","cvss_environmentalscore":"","cvss_environmentalvector":"","metric":22.275,"vulnote":null}