PT-2005-1166 · Microsoft · Exchange Server+2

Published

2005-02-08

·

Updated

2019-04-30

·

CVE-2005-0044

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Windows versions prior to the fixed version Exchange Server versions 5.0 through 2003
Description The issue is related to the OLE component, which does not properly validate the lengths of messages for certain OLE data. This allows remote attackers to execute arbitrary code.
Recommendations For Windows versions prior to the fixed version, update to a version that includes the fix for the issue. For Exchange Server versions 5.0 through 2003, consider disabling the OLE component as a temporary workaround until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0044

Affected Products

Exchange Server
Ole
Windows