Vulnerability Name: | CVE-2004-0840 (CCN-17621) | ||||||||||||||||
Assigned: | 2004-10-12 | ||||||||||||||||
Published: | 2004-10-12 | ||||||||||||||||
Updated: | 2020-04-09 | ||||||||||||||||
Summary: | The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated. | ||||||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0840 Source: CCN Type: CIAC Information Bulletin P-005 Windows SMTP Vulnerability could Allow Remote Code Execution Source: CCN Type: US-CERT VU#394792 Microsoft Windows SMTP component vulnerable to remote code execution Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#394792 Source: CCN Type: Microsoft Security Bulletin MS04-035 Vulnerability in SMTP Service Could Allow Code Execution (885881) Source: CCN Type: Microsoft Security Bulletin MS05-021 Vulnerability in Exchange Server Could Allow Remote Code Execution (894549) Source: BID Type: Third Party Advisory, VDB Entry 11374 Source: CCN Type: BID-11374 Microsoft SMTP Service and Exchange Routing Engine Buffer Overflow Vulnerability Source: MS Type: Patch, Vendor Advisory MS04-035 Source: XF Type: Third Party Advisory, VDB Entry win2k3-smtp-execute-code(17621) Source: XF Type: UNKNOWN win2k3-smtp-execute-code(17621) Source: XF Type: Third Party Advisory, VDB Entry win-ms04035-patch(17660) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:2300 Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:3460 Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:5509 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |