CVE-2002-0054

SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.

Scoring

CVSS base score
0.5
EPSS probability
12.54%
Published
2003-04-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs