vendor:
Exchange Server
by:
Evgeny Pinchuk
7.5
CVSS
HIGH
Heap Overflow
122
CWE
Product Name: Exchange Server
Affected Version From: Microsoft Exchange 2000 SP3
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2005-1080
CPE: a:microsoft:exchange_server:2000:sp3
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1006/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1091/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-0807/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-0809/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-0858/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1020/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1021/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-0806/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-0808/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1007/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-0831/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2010-0831/, https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-953-1/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-18e5428f-ae7c-11d9-837d-000e0c2e438a/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2005-1080/
Platforms Tested: Windows 2000 Server SP4 EN
2005
MS05-021 Exchange X-LINK2STATE Heap Overflow
This exploit takes advantage of a heap overflow vulnerability in Microsoft Exchange, specifically in the X-LINK2STATE chunk. It allows an attacker to execute arbitrary code on a vulnerable system.
Mitigation:
Apply the relevant security patch provided by Microsoft.