CVE-2002-0698Classic Buffer Overflow in Microsoft Exchange Server

Severity
7.5HIGHNVD
EPSS
17.1%
top 4.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateApr 30

Description

Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mw2r-jm5q-xp3p: Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 52022-04-30
CVEList
CVE-2002-0698: Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 52003-04-02
CVE-2002-0698 — Classic Buffer Overflow in Microsoft | cvebase