Executive brief
Multiple Windows-based email servers are vulnerable to a flaw that allows an attacker to crash the mail service. By sending a specially crafted greeting command, a remote user can disrupt email communications for the entire organization. This impact can lead to significant operational delays and loss of incoming business correspondence.
Technical details
A classic buffer overflow (CWE-120) exists in the handling of the SMTP HELO command across multiple Windows NT mail server implementations. An unauthenticated remote attacker can trigger this vulnerability by sending an oversized or malformed HELO string to the SMTP service. This results in memory corruption that typically causes the mail service to crash (Denial of Service), though the CVSS 2.0 score suggests potential for broader impact. Affected products include Microsoft Exchange Server 4.0 and 5.0, IBM Lotus Domino, and various third-party SMTP servers like Ipswitch and MDaemon.
Affected products
- Microsoft Exchange Server 4.0, 5.0
- Ipswitch IMail Server
- Alt-N Technologies MDaemon
- IBM Lotus Domino Mail Server
Timeline
- 1998-01-01: disclosed: Initial publication date in NVD