SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=101501580409373&w=2 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/4205 | Patch Third Party Advisory VDB Entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011 | Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=101501580409373&w=2 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/4205 | Patch Third Party Advisory VDB Entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
20 Nov 2024, 23:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=101501580409373&w=2 - Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/4205 - Patch, Third Party Advisory, VDB Entry | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011 - Patch, Vendor Advisory |
Information
Published : 2002-03-08 05:00
Updated : 2024-11-20 23:38
NVD link : CVE-2002-0054
Mitre link : CVE-2002-0054
CVE.ORG link : CVE-2002-0054
JSON object : View
Products Affected
microsoft
- exchange_server
- windows_2000
CWE
CWE-294
Authentication Bypass by Capture-replay