Title: Microsoft Exchange SMTP Extended Request Overflow
Info
Disclosure
Oct 15, 2003
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Microsoft Exchange contains a flaw that may allow a remote attacker to execute arbitrary code or cause a denial of service. The flaw is due to the SMTP server's improper handling of XEXCH50 verb requests. If an un-authenticated attacker issues a specially-crafted extended verb request, it may exhaust the available memory of the server or in some cases, allow the execution of arbitrary code.