PT-2004-1902 · Microsoft · Windows Server 2003 64-Bit Edition+3
Publicado
2004-10-16
·
Atualizado
2020-04-09
·
CVE-2004-0840
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows XP 64-bit Edition (affected versions not specified)
Microsoft Windows Server 2003 (affected versions not specified)
Microsoft Windows Server 2003 64-bit Edition (affected versions not specified)
Microsoft Exchange Server 2003 (affected versions not specified)
Description:
The issue concerns the SMTP component of certain Microsoft products and the Exchange Routing Engine component of Exchange Server 2003. It allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
Recommendations:
For Microsoft Windows XP 64-bit Edition, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2003, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2003 64-bit Edition, update to a version that includes the fix for this issue.
For Microsoft Exchange Server 2003, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the SMTP component until a patch is available.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Exchange Server 2003
Windows Server 2003
Windows Server 2003 64-Bit Edition
Windows Xp 64-Bit Edition