Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
BID:5413
Info
Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
| Bugtraq ID: | 5413 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-1876 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2002 12:00AM |
| Updated: | Jun 05 2019 11:00AM |
| Credit: | Reported by Dave Aitel <[email protected]>. |
| Vulnerable: |
Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
A vulnerability has been reported for Microsoft Exchange 2000.
Allegedly, Exchange 2000 will experience a denial of service condition when an authenticated user makes many requests. The vulnerability is due to IIS incorrectly allocating licenses to Exchange. Making numerous, rapid requests will exhaust available licenses granted to Exchange by IIS.
A vulnerability has been reported for Microsoft Exchange 2000.
Allegedly, Exchange 2000 will experience a denial of service condition when an authenticated user makes many requests. The vulnerability is due to IIS incorrectly allocating licenses to Exchange. Making numerous, rapid requests will exhaust available licenses granted to Exchange by IIS.
Exploit / POC
Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
Reportedly, these issues may be exploited with the publically available Spike tool, available at the following URL:
http://www.immunitysec.com/spike.html
Reportedly, these issues may be exploited with the publically available Spike tool, available at the following URL:
http://www.immunitysec.com/spike.html
Solution / Fix
Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
References:
References:
- Exchange Server Home Page (Microsoft)