CVE-2002-0368: Medium severity microsoft exchange server vulnerability
The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0368?
CVE-2002-0368 is classified as a denial-of-service vulnerability that can cause significant CPU exhaustion.
How do I fix CVE-2002-0368?
To fix CVE-2002-0368, apply the necessary security updates provided by Microsoft for Exchange Server 2000.
What versions of Microsoft Exchange Server are affected by CVE-2002-0368?
CVE-2002-0368 affects Microsoft Exchange Server 2000, specifically versions SP1 and SP2.
What can attackers do using CVE-2002-0368?
Attackers can send a specially crafted mail message to exploit CVE-2002-0368, leading to denial-of-service by consuming CPU resources.
Is there a workaround for CVE-2002-0368 if I can't apply the patch?
While the primary mitigation is to apply the patch, temporary measures include filtering incoming emails for malformed RFC message attributes.