Vulnerability record · CVE-2003-0714 · published 17 November 2003
CVE-2003-0714: Exchange Internet Mail Service extended verb request causes memory exhaustion
Microsoft · Exchange Server
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 mishandles a certain extended SMTP verb request, allowing remote attackers to exhaust memory and cause a denial of service; the description also notes a possible buffer overflow in Exchange 2000. The flaw is remotely reachable over the SMTP service with no authentication, so any host able to reach the mail port can attempt it.
Description
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote denial of service against internet-facing mail with a very high EPSS score and public exploit references, though no confirmed code execution or KEV listing.
What it is
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 mishandles a certain extended SMTP verb request, allowing remote attackers to exhaust memory and cause a denial of service; the description also notes a possible buffer overflow in Exchange 2000. The flaw is remotely reachable over the SMTP service with no authentication, so any host able to reach the mail port can attempt it.
Impact
An attacker can crash or degrade the mail service through memory exhaustion, disrupting mail delivery; the record hints at a possible buffer overflow in Exchange 2000, but does not confirm code execution.
Attack surface
Reached by directly connecting to the SMTP service and sending a crafted extended verb request; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.776, 99.5th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the Microsoft security bulletin MS03-046 update for Exchange Server 5.5 and Exchange 2000
- Restrict SMTP access to trusted mail relays and hosts using firewall or network ACLs
- Disable or block unnecessary extended SMTP verbs at the mail gateway where feasible
- Monitor Exchange memory and service availability for abnormal spikes or restarts
Detection
- Alert on Exchange SMTP service crashes, restarts or memory exhaustion events
- Log and review SMTP sessions issuing unusual or malformed extended verb commands
- Baseline normal SMTP verb usage and flag deviations from expected mail flow
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=106682909006586&w=2 | Mailing ListThird Party Advisory |
| http://www.cert.org/advisories/CA-2003-27.html | Third Party AdvisoryUS Government Resource |
| http://www.kb.cert.org/vuls/id/422156 | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/8838 | ExploitPatchThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-046 | PatchVendor Advisory |
| http://marc.info/?l=bugtraq&m=106682909006586&w=2 | Mailing ListThird Party Advisory |
| http://www.cert.org/advisories/CA-2003-27.html | Third Party AdvisoryUS Government Resource |
| http://www.kb.cert.org/vuls/id/422156 | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/8838 | ExploitPatchThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-046 | PatchVendor Advisory |
Track CVE-2003-0714 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0714), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.