Buffer Overrun in Microsoft Exchange Server 5.5
A buffer overrun vulnerability exists in Microsoft Exchange Server 5.5 that can let an attacker remotely compromise the server.
July 24, 2002
ReportedJuly 24, 2002, by Microsoft.
VERSIONAFFECTED
Microsoft Exchange Server 5.5
DESCRIPTION
Abuffer overrun vulnerability exists in Microsoft Exchange Server 5.5 that canlet an attacker remotely compromise the server. This vulnerability is the resultof an unchecked buffer in the Internet Mail Connector (IMC) code that generatesthe response to the Extended Hello protocol command. If an attacker sends randomdata in a message in which the total length of the message exceeds a specificvalue, the data can overrun the buffer and cause the IMC to fail. If an attackeroverruns the buffer with specific data, the attacker can run code under thesecurity context of the IMC, which by default runs as an Exchange 5.5 ServiceAccount.
VENDORRESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-037("Server Response To SMTP Client EHLO Command Results In BufferOverrun") to address this vulnerability and recommends that affected usersdownload and apply the appropriate patchmentioned in the bulletin.
CREDIT
Discoveredby DanIngevaldsonofInternet Security Systems.
Read more about:
MicrosoftAbout the Author
You May Also Like