Exchange server encapsulated addresses could allow third-party relaying
| exchange-relay (3107) |
Description:
In Microsoft Exchange, when at least one Internet Mail Service is configured, a vulnerability could allow a remote user to relay mail off of the server to other users by using encapsulated SMTP addresses. This vulnerability could allow someone to use your site to send spam email (electronic unsolicited message disseminated to a large number of recipients).
Consequences:
Bypass Security
Remedy:
Apply the post-SP2 imc-fix patch, as listed in Microsoft Security Bulletin MS99-027. See References.
Note: The post-SP2 imc-fix patch should be applied to the Microsoft Exchange Server version 5.5 to eliminate the `Encapsulated SMTP Address¿ vulnerability by making encapsulated SMTP addresses subject to the same anti-relay protections as non-encapsulated SMTP addresses.
References:
- CIAC Information Bulletin J-056: Microsoft 'Encapsulated SMTP Address' Vulnerability.
- Microsoft Knowledge Base Article 237927: XIMS: Messages Sent to Encapsulated SMTP Address Are Rerouted Even Though Rerouting Is Disabled.
- Microsoft Security Bulletin MS99-027: Patch Available for 'Encapsulated SMTP Address' Vulnerability.
- BID-567: NT Exchange Server Encapsulated SMTP Address Vulnerability
- CVE-1999-0512: A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
- CVE-1999-0682: Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
Platforms Affected:
- Microsoft Exchange Server 5.5
- Microsoft Windows 2000
- Microsoft Windows NT 4.0
Reported:
Aug 06, 1999
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
