CVE-2000-0833

WinSMTP 1.06f and 2.X - Denial of Service via Long USER or HELO Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0833. PoCs published by Guido Bakker.

AI-analyzed exploit summary This Perl script exploits a buffer overflow vulnerability in WinSMTP's SMTP component by sending an oversized HELO command (170 bytes) to trigger a denial of service (DoS) or potential arbitrary code execution. The exploit establishes a TCP connection to the SMTP port and sends the malicious payload.

Description

Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Guido Bakker · perldoswindows
https://www.exploit-db.com/exploits/20221

This Perl script exploits a buffer overflow vulnerability in WinSMTP's SMTP component by sending an oversized HELO command (170 bytes) to trigger a denial of service (DoS) or potential arbitrary code execution. The exploit establishes a TCP connection to the SMTP port and sends the malicious payload.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: WinSMTP (Jack De Winter's mail daemon)
No auth needed
Prerequisites: Network access to the target SMTP port (25)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5255
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1680
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/81693

Scores

EPSS 0.1042
EPSS Percentile 95.2%

Details

Status published
Products (2)
jack_de_winter/winsmtp 1.6f
jack_de_winter/winsmtp 2.x
Published Nov 14, 2000
Tracked Since Feb 18, 2026