Rapid7 Vulnerability & Exploit Database

Microsoft Windows 2000 and Microsoft Exchange SMTP NTLM Authentication Bypass

Back to Search

Microsoft Windows 2000 and Microsoft Exchange SMTP NTLM Authentication Bypass

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
03/08/2002
Created
07/25/2018
Added
11/01/2004
Modified
07/16/2012

Description

The SMTP service of Microsoft Windows 2000 and Microsoft Exchange Internet Mail Connector (IMC) may allow users to bypass by using the anonymous (NULL) account. This allows unauthorized users to access the mail system for relaying.

Solution(s)

  • install-microsoft-patch-146e4a9552afc1f4eb86ddceef2627ad
  • install-microsoft-patch-8e6a6a44a82c61a6a9b06ce93ae73874

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;