← Vulnerability feed

Vulnerability record · CVE-2003-0714 · published 17 November 2003

CVE-2003-0714: Exchange Internet Mail Service extended verb request causes memory exhaustion

Microsoft · Exchange Server

The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 mishandles a certain extended SMTP verb request, allowing remote attackers to exhaust memory and cause a denial of service; the description also notes a possible buffer overflow in Exchange 2000. The flaw is remotely reachable over the SMTP service with no authentication, so any host able to reach the mail port can attempt it.

7.5 CVSS 2.0 High EPSS 78% · top 0.5% CWE-400 · Uncontrolled resource consumption
7.5CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote denial of service against internet-facing mail with a very high EPSS score and public exploit references, though no confirmed code execution or KEV listing.

What it is

The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 mishandles a certain extended SMTP verb request, allowing remote attackers to exhaust memory and cause a denial of service; the description also notes a possible buffer overflow in Exchange 2000. The flaw is remotely reachable over the SMTP service with no authentication, so any host able to reach the mail port can attempt it.

Impact

An attacker can crash or degrade the mail service through memory exhaustion, disrupting mail delivery; the record hints at a possible buffer overflow in Exchange 2000, but does not confirm code execution.

Attack surface

Reached by directly connecting to the SMTP service and sending a crafted extended verb request; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.776, 99.5th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the Microsoft security bulletin MS03-046 update for Exchange Server 5.5 and Exchange 2000
  • Restrict SMTP access to trusted mail relays and hosts using firewall or network ACLs
  • Disable or block unnecessary extended SMTP verbs at the mail gateway where feasible
  • Monitor Exchange memory and service availability for abnormal spikes or restarts

Detection

  • Alert on Exchange SMTP service crashes, restarts or memory exhaustion events
  • Log and review SMTP sessions issuing unusual or malformed extended verb commands
  • Baseline normal SMTP verb usage and flag deviations from expected mail flow

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=106682909006586&w=2 Mailing ListThird Party Advisory
http://www.cert.org/advisories/CA-2003-27.html Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/422156 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/8838 ExploitPatchThird Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-046 PatchVendor Advisory
http://marc.info/?l=bugtraq&m=106682909006586&w=2 Mailing ListThird Party Advisory
http://www.cert.org/advisories/CA-2003-27.html Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/422156 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/8838 ExploitPatchThird Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-046 PatchVendor Advisory

Track CVE-2003-0714 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21410Microsoft Exchange Server improper authentication privilege escalationCVE-2024-21410 is an improper authentication (CWE-287) elevation of privilege flaw in Microsoft Exchange Server. It is network-reachable with no priv…KEVEPSS 13%analysed9.1CVE-2021-34473Microsoft Exchange Server SSRF Enables Remote Code ExecutionCVE-2021-34473 is a critical server-side request forgery (SSRF) flaw in Microsoft Exchange Server that leads to remote code execution. It is part of …KEVEPSS 100%analysed9.1CVE-2021-26855Microsoft Exchange Server SSRF enabling remote code executionCVE-2021-26855 is a server-side request forgery (CWE-918) in Microsoft Exchange Server that is part of the ProxyLogon exploit chain and can lead to r…KEVEPSS 100%analysed9.0CVE-2021-34523Microsoft Exchange Server privilege escalation flawCVE-2021-34523 is a privilege escalation vulnerability in Microsoft Exchange Server. It is a component of the ProxyShell exploit chain, where it is u…KEVEPSS 100%analysed8.8CVE-2023-21529Microsoft Exchange Server deserialization flaw enables remote code executionCVE-2023-21529 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Exchange Server that allows remote code execution. It carr…KEVEPSS 59%analysed8.8CVE-2022-41080Microsoft Exchange Server elevation of privilegeCVE-2022-41080 is an elevation of privilege vulnerability in Microsoft Exchange Server. A network-reachable attacker with low privileges can exploit …KEVEPSS 77%analysed8.8CVE-2022-41040Microsoft Exchange Server SSRF elevation of privilegeCVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges…KEVEPSS 100%analysed8.8CVE-2021-42321Microsoft Exchange Server remote code execution flawCVE-2021-42321 is a remote code execution vulnerability in Microsoft Exchange Server. It is remotely reachable over the network with low complexity, …KEVEPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2003-0714), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.