CVE-2002-0698
Estado: ModificadaAlta (7.5)—
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 20%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-120
Referencias
- http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20759
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ326322
- http://www.iss.net/security_center/static/9658.php
- http://www.securityfocus.com/bid/5306
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-037
- http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20759
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ326322
- http://www.iss.net/security_center/static/9658.php
- http://www.securityfocus.com/bid/5306
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-037
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0698",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-08-12T04:00:00.000",
"references": [
{
"url": "http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20759",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ326322",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/9658.php",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5306",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-037",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20759",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ326322",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/9658.php",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/5306",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-037",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response."
},
{
"lang": "es",
"value": "Desbordamiento de búfer en Internet Mail Connector (IMC) para Microsoft Exchange Server 5.5 permite que atacantes remotos ejecuten código arbitrario por medio de una petición EHLO desde un sistema con un nombre largo obtenido por búsqueda DNS inversa, lo cual provoca el desbordamiento de búfer en la respuesta de IMC."
}
],
"lastModified": "2026-06-16T21:57:57.967",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4F9C143-4734-4E5D-9281-F51513C5CAAF"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD3E2F18-A369-4767-ACEF-38DB40EEC6D4"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC01670D-4550-4034-86A5-7879B6334241"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B80A57A1-7B9F-4C07-ADAA-DBC4687F1EFC"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3983529-F4E3-4883-97AF-5BFC87AC3E86"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}