Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
BID:5412
Info
Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
| Bugtraq ID: | 5412 |
| Class: | Unknown |
| CVE: |
CVE-2002-1873 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2002 12:00AM |
| Updated: | Jun 05 2019 11:00AM |
| Credit: | Reported by Dave Aitel <[email protected]>. |
| Vulnerable: |
Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
Microsoft Exchange makes usage of the MSRPC, the Microsoft Remote Procedure Call framework. Several potential issues have been reported in MSRPC, as used in conjunction with Microsoft Exchange.
Malformed MSRPC calls may result in either the Exchange server or the underlying operating system crashing. A denial of service condition may result, requiring a restart in order to regain normal functionality.
Microsoft Exchange makes usage of the MSRPC, the Microsoft Remote Procedure Call framework. Several potential issues have been reported in MSRPC, as used in conjunction with Microsoft Exchange.
Malformed MSRPC calls may result in either the Exchange server or the underlying operating system crashing. A denial of service condition may result, requiring a restart in order to regain normal functionality.
Exploit / POC
Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
Reportedly, these issues may be exploited with the publically available Spike tool, available at the following URL:
http://www.immunitysec.com/spike.html
Reportedly, these issues may be exploited with the publically available Spike tool, available at the following URL:
http://www.immunitysec.com/spike.html
Solution / Fix
Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
References:
References:
- Exchange Server Home Page (Microsoft)