Authentication Error in SMTP Service Could Allow Mail Relaying New
A vulnerability exists in the Windows 2000 SMTP service that could enable an unauthorized user to conduct mail relaying by using a Windows 2000 server.
Issue
An SMTP service installs by default as part of Windows 2000 server products, and can be selected for installation on Windows 2000 Professional. A vulnerability results because of a flaw in the authentication process used by the service. The vulnerability could allow an unauthorized user to successfully authenticate to the service using incorrect credentials. An attacker who exploited the vulnerability could gain user-level privileges on the SMTP service, thereby enabling the attacker to use the service but not to administer it. The most likely purpose in exploiting the vulnerability would be to perform mail relaying via the server.
Affected Products
- Microsoft Windows 2000
Download
Patch: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=31181
Further Details
Source: Microsoft Corporation
Reference: Microsoft Corporation
Updated: July 5, 2001
>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<
















