SMTP: Collaboration Data Objects Vulnerability
This signature detects the SMTP transmission of a maliciously crafted e-mail, designed to exploit a vulnerability in Microsoft IIS.
Extended Description
Microsoft CDO is susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the library to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer. This issue presents itself when an attacker sends a specifically crafted email message to an email server utilizing the affected library. This issue allows remote attackers to execute arbitrary machine code in the context of the application utilizing the library.
Affected Products
Microsoft windows_xp_media_center_edition
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
srx-branch-12.3
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx-12.3
vmx-19.3
srx-12.3
Nortel_networks
Microsoft
7.5