Arbitrary Code Execution Vulnerability in Microsoft Exchange Server

Reported October 15, 2003, by Microsoft.

VERSIONS AFFECTED

  • Microsoft Exchange 2000 Server Service Pack 3 (SP3)
  • Exchange Server 5.5 SP4

DESCRIPTION

·         A vulnerability in Exchange Server can result in a Denial of Service (DoS) condition or the execution of arbitrary code on the vulnerable system. This vulnerability stems from a flaw in the Internet Mail Service that can permit an unauthenticated attacker to connect to the SMTP port on an Exchange server and issue a specially crafted extended verb request. This scenario can result in the allocation of a large amount of memory and potentially cause a buffer overrun that could permit the attacker to run malicious programs in the security context of the SMTP service.

VENDOR RESPONSE

Microsoft has released security bulletin MS03-046, "Vulnerability in Exchange Server Could Allow Arbitrary Code Execution (829436)," which addresses this vulnerability, and recommends that affected users immediately apply the appropriate patch listed in the bulletin.

CREDIT

Discovered by Joăo Gouveia.

Please or Register to post comments.

IT/Dev Connections Exchange Server

Las Vegas
September 30th - October 4th

Paul ThurottYou'll have the opportunity to experience:
• Future Deopyments
and Integrations
• Hybrid Deployments
• Exchange Online
• Windows 8 Deployment
and much more!

Come See Tony Redmond & Mark Minasi in Person!

Early Registration Now Open

Current Issue

May 2013 - The NameTranslate object is useful when you need to translate Active Directory object names between different formats, but it's awkward to use from PowerShell. Here's a PowerShell script that eliminates the awkwardness.

CURRENT ISSUE / ARCHIVE / SUBSCRIBE

Windows Forums

Get answers to questions, share tips, and engage with the Windows Community in our Forums.