CVE-2001-0666: Low severity Microsoft Exchange Server vulnerability
Published Oct 30, 2001
·Updated
Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
Affected Software
1 affected component
Microsoft Exchange Server=2000
Remediation
Event History
Oct 30, 2001
CVE Published
05:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0666?
CVE-2001-0666 is classified as a denial of service vulnerability.
2
How does CVE-2001-0666 affect users of Outlook Web Access?
CVE-2001-0666 allows an authenticated user to cause high CPU consumption, leading to denial of service.
3
What versions of Microsoft Exchange are affected by CVE-2001-0666?
CVE-2001-0666 affects Microsoft Exchange Server 2000.
4
What type of request triggers CVE-2001-0666?
CVE-2001-0666 is triggered by a malformed request for a deeply nested folder within a user's mailbox.
5
How can administrators mitigate the impact of CVE-2001-0666?
Administrators can mitigate CVE-2001-0666 by applying available patches and limiting access to nested folders.