Buffer Overrun in Microsoft Exchange Server 5.5

A buffer overrun vulnerability exists in Microsoft Exchange Server 5.5 that can let an attacker remotely compromise the server.

Ken Pfeil

July 24, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedJuly 24, 2002, by Microsoft.

VERSIONAFFECTED

 

  • Microsoft Exchange Server 5.5

 

DESCRIPTION

 

Abuffer overrun vulnerability exists in Microsoft Exchange Server 5.5 that canlet an attacker remotely compromise the server. This vulnerability is the resultof an unchecked buffer in the Internet Mail Connector (IMC) code that generatesthe response to the Extended Hello protocol command. If an attacker sends randomdata in a message in which the total length of the message exceeds a specificvalue, the data can overrun the buffer and cause the IMC to fail. If an attackeroverruns the buffer with specific data, the attacker can run code under thesecurity context of the IMC, which by default runs as an Exchange 5.5 ServiceAccount.

 

VENDORRESPONSE

 

Thevendor, Microsoft, has released SecurityBulletin MS02-037("Server Response To SMTP Client EHLO Command Results In BufferOverrun") to address this vulnerability and recommends that affected usersdownload and apply the appropriate patchmentioned in the bulletin.

 

CREDIT
Discoveredby DanIngevaldsonofInternet Security Systems.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like