CVE-2002-0054
Last modified
CVE-2002-0054 is a vulnerability of currently unknown severity. SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.. EPSS estimates a 22.33% chance of exploitation in the next 30 days.
Description
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Exchange Server | 5.5 |
| Microsoft | Windows 2000 | All versions |
References
- http://marc.info/?l=bugtraq&m=101501580409373&w=2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/4205Patch, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=101501580409373&w=2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/4205Patch, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0054?
How severe is CVE-2002-0054?
How do I fix CVE-2002-0054?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0048Multiple signedness errors (mixed signed and unsigned number…
- CVE-2002-0049Microsoft Exchange Server 2000 System Attendant gives "Every…
- CVE-2002-0050Buffer overflow in AuthFilter ISAPI filter on Microsoft Comm…
- CVE-2002-0051Windows 2000 allows local users to prevent the application o…7.8
- CVE-2002-0052Internet Explorer 6.0 and earlier does not properly handle V…
- CVE-2002-0053Buffer overflow in SNMP agent service in Windows 95/98/98SE,…
- CVE-2002-0055SMTP service in Microsoft Windows 2000, Windows XP Professio…
- CVE-2002-0056Buffer overflow in SQL Server 7.0 and 2000 allows remote att…
- CVE-2002-0057XMLHTTP control in Microsoft XML Core Services 2.6 and later…
- CVE-2002-0058Vulnerability in Java Runtime Environment (JRE) allows remot…
- CVE-2002-0059The decompression algorithm in zlib 1.1.3 and earlier, as us…9.8
- CVE-2002-0060IRC connection tracking helper module in the netfilter subsy…
Are you affected by CVE-2002-0054?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
