PT-2004-1902 · Microsoft · Windows Server 2003 64-Bit Edition+3
Published
2004-10-16
·
Updated
2020-04-09
·
CVE-2004-0840
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows XP 64-bit Edition (affected versions not specified)
Microsoft Windows Server 2003 (affected versions not specified)
Microsoft Windows Server 2003 64-bit Edition (affected versions not specified)
Microsoft Exchange Server 2003 (affected versions not specified)
Description:
The issue concerns the SMTP component of certain Microsoft products and the Exchange Routing Engine component of Exchange Server 2003. It allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
Recommendations:
For Microsoft Windows XP 64-bit Edition, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2003, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2003 64-bit Edition, update to a version that includes the fix for this issue.
For Microsoft Exchange Server 2003, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the SMTP component until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server 2003
Windows Server 2003
Windows Server 2003 64-Bit Edition
Windows Xp 64-Bit Edition