CVE-2002-0698
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 20.26% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- microsoft/exchange server
- Source
- cve@mitre.org
References
- http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20759Broken Link
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ326322
- http://www.iss.net/security_center/static/9658.phpBroken Link
- http://www.securityfocus.com/bid/5306Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-037Patch, Vendor Advisory
- http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20759Broken Link
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ326322
- http://www.iss.net/security_center/static/9658.phpBroken Link
- http://www.securityfocus.com/bid/5306Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-037Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.