CVE-2005-0560

Microsoft Exchange Server - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Evgeny Pinchuk · perlremotewindows
https://www.exploit-db.com/exploits/947

Scores

EPSS 0.7286
EPSS Percentile 98.8%

Details

CWE
CWE-787
Status published
Products (2)
microsoft/exchange_server 2000
microsoft/exchange_server 2003
Published May 02, 2005
Tracked Since Feb 18, 2026