vendor:
Mercury Mail Transport System
by:
Muts
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Mercury Mail Transport System
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2004-1212
CPE: a:mercury:mercury
Platforms Tested:
2004
Mercury-4444-multi.pl Remote Buffer Overflow Vulnerability
This script is a perl exploit for the Mercury Mail Transport System. It exploits a remote buffer overflow vulnerability to execute arbitrary code on the target system. The vulnerability exists in the handling of the -o command line option. By providing a long argument to this option, an attacker can overflow a buffer and overwrite the return address, leading to remote code execution. The exploit supports multiple versions of Windows, including Windows 2000 SP4 and Windows XP SP1.
Mitigation:
Apply the appropriate patch provided by the vendor. Disable the affected service if it is not required.