PT-2005-1166 · Microsoft · Exchange Server+2
Published
2005-02-08
·
Updated
2019-04-30
·
CVE-2005-0044
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Windows versions prior to the fixed version
Exchange Server versions 5.0 through 2003
Description
The issue is related to the OLE component, which does not properly validate the lengths of messages for certain OLE data. This allows remote attackers to execute arbitrary code.
Recommendations
For Windows versions prior to the fixed version, update to a version that includes the fix for the issue.
For Exchange Server versions 5.0 through 2003, consider disabling the OLE component as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exchange Server
Ole
Windows