CVE-2004-0840
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 30.29% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/exchange server · microsoft/windows server 2003 · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/394792Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/11374Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-035Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17621Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17660Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2300Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3460Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5509Third Party Advisory
- http://www.kb.cert.org/vuls/id/394792Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/11374Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-035Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17621Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17660Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2300Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3460Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5509Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.