漏洞信息详情
多款Microsoft产品SMTP组件和Exchange Routing Engine组件输入验证错误漏洞
- CNNVD编号:CNNVD-200411-026
- 危害等级: 超危
- CVE编号:
CVE-2004-0840
- 漏洞类型:
输入验证错误
- 发布时间:
2004-10-12
- 威胁类型:
远程
- 更新时间:
2020-04-10
- 厂 商:
microsoft - 漏洞来源:
Microsoft Security… -
漏洞简介
多款Microsoft产品中的SMTP组件和Exchange Routing Engine组件存在输入验证错误漏洞。远程攻击者可借助恶意的DNS响应消息利用该漏洞执行任意代码。以下产品及版本受到影响:Microsoft Windows XP(64-bit)(SMTP),Windows Server 2003(SMTP),Windows Server 2003(64-bit)(SMTP),Exchange Server 2003(Exchange Routing Engine)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-035
参考网址
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2300
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/17621
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/17660
来源:BID
链接:https://www.securityfocus.com/bid/11374
来源:MS
链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-035
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3460
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5509
来源:CERT-VN