Microsoft Windows 2000 Authentication Flaw Could A Q313450

An SMTP service installs by default as part of Windows 2000 server products and as part of the Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5. (The IMC, also known as the Microsoft Exchange Internet Mail Service, provides access and message exchange to and from any system that uses SMTP). A vulnerability results in both services because of a flaw in the way they handle a valid response from the NTLM authentication layer of the underlying operating system.By design, the Windows 2000 SMTP service and the Exchange Server 5.5 IMC, upon receiving notification from the NTLM authentication layer that a user has been authenticated, should perform additional checks before granting the user access to the service. The vulnerability results because the affected services dont perform this additional checking correctly. In some cases, this could result in the SMTP service granting access to a user solely on the basis of their ability to successfully authenticate to the server.An attacker who exploited the vulnerability could gain only user-level privileges on the SMTP service, thereby enabling the attacker to use the service but not to administer it. The most likely purpose in exploiting the vulnerability would be to perform mail relaying via the server.

An SMTP service installs by default as part of Windows 2000 server products and as part of the Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5. (The IMC, also known as the Microsoft Exchange Internet Mail Service, provides access and

 
  • Microsoft Windows 2000 Authentication Flaw Could A Q313450
  • 5am Code
  • Windows 2000
  • Shareware
  • 0 Kb
  • 4
 
 

Review Microsoft Windows 2000 Authentication Flaw Could A Q313450

  • captcha
 

Other software of 5am Code
  • 2007 Microsoft Office Suite Service Pack 1  v.1.0The 2007 Microsoft Office suite Service Pack 1 delivers important customer-requested stability and performance improvements, while incorporating further enhancements to user security. This service pack also includes all of the updates released for
  • 2007 Office System Converter: Microsoft Filter Pack  v.1.0Will install and register IFilters with the Microsoft Windows Indexing Service.The package will install and register IFilters with the Microsoft Windows Indexing Service. These IFilters are used by Microsoft Search products to index the contents of

New Miscellaneous software
  • CDAID  v.3.20CD Audio Information Downloader ermittelt CD Infos wiez.B. CD K?r und Songtitel von freedb aus dem Internet. Kein ?erlegen mehr, wie der Titel von Song 4 ist oder wie die eingelegten CD im Laufwerk hei?.
  • The TUT Video  v.1.30TUT - The Video. Video of TUT, The Ultimate Troubleshooter, the most complete and most effective PC Tuning program ever written.
  • NCAA Tournament Courtside  v.1.5.1Feel like you're court-side at the game while staying keyboard-side at your computer! The NCAA Basketball Courtside Widget lets you track men's and women's college basketball scores in real-time, stay on top of the NCAA tournament action during the
  • Autumn Treasures screensaverAutumn Treasures screensaver is a new, marvelous sceensaver. This free screensaver from American Greetings showcases the fruits of the harvest, including reminders of the traditions, memories and joys of the Thanksgiving holiday. Images include