Exchange 2000 Gets DoS Patch
Microsoft releases a patch for a new denial-of-service vulnerability in Exchange 2000.Microsoft Corp. on Wednesday released a patch for a new denial-of-service vulnerability in Exchange 2000. The problem lies in the way the server handles malformed SMTP mail messages. When it receives such a message, Exchanges Store service uses all of the available CPU cycles in trying to process the message. There is no way for an attacker to view or delete data on the vulnerable server.
To exploit the vulnerability, an attacker would have to create a raw SMTP message with the specially malformed attribute. He would then have to pass it directly to the Exchange server.