vendor:
Exchange Server
by:
Charles Truscott
9
CVSS
CRITICAL
Memory Corruption
CWE
Product Name: Exchange Server
Affected Version From: Exchange 2003 SP0
Affected Version To: Exchange 2003 SP0
Patch Exists: NO
Related CWE: CVE-Unknown
CPE: a:microsoft:exchange_server:2003:sp0
Platforms Tested: Windows Server 2003 R2
Unknown
Exchange 2003 SP0 base64-MIME memory corruption
This exploit targets a memory corruption vulnerability in Exchange 2003 SP0. The vulnerability is triggered when processing a base64-MIME encoded email. By sending a specially crafted email, an attacker can corrupt the memory of the Exchange server, potentially leading to remote code execution.
Mitigation:
Apply the latest patches and updates for Exchange 2003 SP0. Consider upgrading to a newer version of Exchange if possible.