Microsoft Windows SMTP Service...

- AV AC AU C I A
发布: 2002-02-27
修订: 2025-04-13

A vulnerability has been reported in the Microsoft Windows 2000 SMTP service and Microsoft Exchange Server Internet Mail Connector service. This issue may allow an attacker to gain unauthorized user-level access to the SMTP service on a vulnerable host. The consequences of this issue are that an attacker may potentially exploit this vulnerability to turn the server into a mail relay. Systems running Microsoft Exchange 2000 are not prone to this issue. ** The advisory on this issue released by the BindView RAZOR team states that a user connecting through a NULL session can also exploit this vulnerability. Support for NULL sessions is enabled by default. This enables anonymous users who have not authenticated through NTLM to use the server as a mail relay.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息