CVE-2004-0840: Input Validation
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0840?
CVE-2004-0840 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2004-0840?
To fix CVE-2004-0840, apply the latest security patches provided by Microsoft for the affected software.
What are the affected systems for CVE-2004-0840?
CVE-2004-0840 affects Microsoft Windows XP 64-bit Edition, Windows Server 2003, and Exchange Server 2003.
Can CVE-2004-0840 be exploited remotely?
Yes, CVE-2004-0840 can be exploited remotely by sending a malicious DNS response to the SMTP component.
What could happen if CVE-2004-0840 is exploited?
If exploited, CVE-2004-0840 could allow attackers to execute arbitrary code on the affected system.