CVE-2003-0714
Exchange Server 5.5 and 2000 - Denial of Service via SMTP Extended Verb Request
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2003-0714.
PoCs published by Metasploit, H D Moore, hdm, aushack, including Metasploit module exploits/windows/smtp/ms03_046_exchange2000_xexch50.
AI-analyzed exploit summary This is a Metasploit module exploiting a heap overflow in Microsoft Exchange 2000 via the XEXCH50 command. It attempts to achieve remote code execution by overwriting heap memory with a crafted payload.
Description
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.
Exploits (3)
This is a Metasploit module exploiting a heap overflow in Microsoft Exchange 2000 via the XEXCH50 command. It attempts to achieve remote code execution by overwriting heap memory with a crafted payload.
This Perl script exploits CVE-2003-0714, a heap overflow vulnerability in Microsoft Exchange Server's SMTP service. It includes both a check mode to verify vulnerability and a crash mode to trigger a denial-of-service (DoS) by sending a malformed XEXCH50 command with a negative size value.
This is a Metasploit module exploiting a heap overflow vulnerability in Microsoft Exchange 2000 via the XEXCH50 command. It attempts to achieve remote code execution by overwriting heap memory with a crafted payload, though it is noted to be highly unreliable.