Microsoft Windows/Exchange SMTP DNS Lookup Overflow (885881)

This script is Copyright (C) 2004-2012 Tenable Network Security, Inc.


Synopsis :

The remote SMTP server is affected by a buffer overflow vulnerability.

Description :

The remote host is running a version of Microsoft SMTP server which
fails to validate DNS response data. An attacker can exploit this flaw
to execute arbitrary code subject to the priviliges of the SMTP
application server process.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms04-035

Solution :

Apply the bulletin referenced above.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.4
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: SMTP problems

Nessus Plugin ID: 15464 ()

Bugtraq ID: 11374

CVE ID: CVE-2004-0840

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial