Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
BID:2988
Info
Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
| Bugtraq ID: | 2988 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2001 12:00AM |
| Updated: | Jul 05 2001 12:00AM |
| Credit: | Discovered by Joao Gouveia <[email protected]> and published in a Microsoft Security Bulletin MS01-037 on July 5, 2001. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
Due to a flaw in the authentication process of the SMTP service in Windows 2000, it is possible for remote host to successfully authenticate and use the SMTP services as an authenticated user.
This may lead to abuse of SMTP services, such as mass e-mail relaying.
Due to a flaw in the authentication process of the SMTP service in Windows 2000, it is possible for remote host to successfully authenticate and use the SMTP services as an authenticated user.
This may lead to abuse of SMTP services, such as mass e-mail relaying.
Solution / Fix
Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
Solution:
Microsoft has released a patch which addresses this issue:
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Server
Solution:
Microsoft has released a patch which addresses this issue:
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Server