PT-2004-1902 · Microsoft · Windows Server 2003 64-Bit Edition+3

Publicado

2004-10-16

·

Atualizado

2020-04-09

·

CVE-2004-0840

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Windows XP 64-bit Edition (affected versions not specified) Microsoft Windows Server 2003 (affected versions not specified) Microsoft Windows Server 2003 64-bit Edition (affected versions not specified) Microsoft Exchange Server 2003 (affected versions not specified)
Description: The issue concerns the SMTP component of certain Microsoft products and the Exchange Routing Engine component of Exchange Server 2003. It allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
Recommendations: For Microsoft Windows XP 64-bit Edition, update to a version that includes the fix for this issue. For Microsoft Windows Server 2003, update to a version that includes the fix for this issue. For Microsoft Windows Server 2003 64-bit Edition, update to a version that includes the fix for this issue. For Microsoft Exchange Server 2003, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the SMTP component until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-0840

Produtos afetados

Exchange Server 2003
Windows Server 2003
Windows Server 2003 64-Bit Edition
Windows Xp 64-Bit Edition