Microsoft Windows SMTP Incorrect Credentials Authentication Bypass

This script is Copyright (C) 2001-2012 Tenable Network Security, Inc.


Synopsis :

The remote SMTP server is vulnerable to an authentication
bypass.

Description :

The remote SMTP server is vulnerable to a flaw in its
authentication process.

This vulnerability allows any unauthorized user to successfully
authenticate and use the remote SMTP server.

An attacker may use this flaw to use this SMTP server
as a spam relay.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms01-037

Solution :

Apply the appropriate MS01-037 patches from Microsoft or
upgrade to the latest service pack.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.5
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: SMTP problems

Nessus Plugin ID: 10703 ()

Bugtraq ID: 2988

CVE ID: CVE-2001-0504