PT-2005-1609 · Microsoft · Exchange Server
Ben Layer
+1
·
Published
2005-04-13
·
Updated
2025-09-22
·
CVE-2005-0560
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Exchange Server versions 2000 through 2003
Description
A heap-based buffer overflow issue exists in the SvrAppendReceivedChunk function in xlsasink.dll, which is part of the SMTP service. This allows remote attackers to execute arbitrary code by sending a crafted X-LINK2STATE extended verb request to the SMTP port.
Recommendations
For Exchange Server versions 2000 through 2003, consider restricting access to the SMTP port until a fix is available. As a temporary workaround, disabling the xlsasink.dll module may help minimize the risk of exploitation.
Exploit
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server