Vulnerability record · CVE-2003-0264 · published 27 May 2003
CVE-2003-0264: SLMail 5.1.0.4420 multiple buffer overflows allow remote code execution
Seattle Lab Software · Slmail
SLMail 5.1.0.4420 contains multiple buffer overflows reachable through SMTP and POP3 commands, including long EHLO and XTRN arguments to slmail.exe and long input to POPPASSWD or the POP3 password field. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code on the mail server, making this a serious pre-auth risk for any internet-facing deployment.
Description
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPre-authentication remote code execution with public exploit code and a very high EPSS score, though the legacy product and lack of KEV listing temper the rating.
What it is
SLMail 5.1.0.4420 contains multiple buffer overflows reachable through SMTP and POP3 commands, including long EHLO and XTRN arguments to slmail.exe and long input to POPPASSWD or the POP3 password field. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code on the mail server, making this a serious pre-auth risk for any internet-facing deployment.
Impact
An attacker gains remote code execution in the context of the SLMail service, which typically runs with system-level privileges on Windows hosts. That allows full compromise of the mail server and any data or credentials it handles.
Attack surface
The flaws are reached over the network through the SMTP and POP3 listeners on the mail server; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N. Any host exposing these services is directly reachable.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at roughly 0.715 (99.4th percentile), and public references include a Packet Storm remote code execution exploit and a vendor advisory, indicating mature public exploit code exists.
What to do
- Apply the vendor patch or upgrade referenced in the Next Generation Security Software advisory; if no supported fix exists, retire or replace SLMail 5.1.0.4420.
- Restrict SMTP and POP3 access to trusted networks and block these ports from the internet where the service is not required to be public.
- Run the SLMail service under a low-privilege account and isolate the host on a segmented network to limit post-exploitation reach.
- Enable network-level filtering or an IPS signature for oversized EHLO, XTRN, POPPASSWD and POP3 password arguments.
- Monitor vendor and CISA advisories for updated guidance since the product is legacy and likely unsupported.
Detection
- Inspect SMTP and POP3 logs for abnormally long EHLO, XTRN, POPPASSWD or password arguments that exceed normal client behavior.
- Alert on SLMail service crashes or restarts, which can indicate failed buffer overflow attempts.
- Monitor for unexpected child processes or outbound connections spawned by slmail.exe, consistent with code execution.
- Use network monitoring to flag exploit traffic matching known SLMail overflow patterns from public exploit code.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0264 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0264), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.