Vulnerability record · CVE-2003-1200 · published 29 December 2003
CVE-2003-1200: Alt-N MDaemon FORM2RAW.exe stack buffer overflow via From parameter
AAlt N · Mdaemon
FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 contains a stack-based buffer overflow reachable through a long From parameter passed to Form2Raw.cgi. A remote attacker can overwrite stack memory and potentially execute arbitrary code on the mail server. The flaw affects an unauthenticated network-reachable component, making it a serious pre-auth risk for exposed MDaemon installations.
Description
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution in an internet-facing mail component with public exploit references and very high EPSS, though no KEV listing or confirmed in-the-wild ransomware use.
What it is
FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 contains a stack-based buffer overflow reachable through a long From parameter passed to Form2Raw.cgi. A remote attacker can overwrite stack memory and potentially execute arbitrary code on the mail server. The flaw affects an unauthenticated network-reachable component, making it a serious pre-auth risk for exposed MDaemon installations.
Impact
Successful exploitation can allow a remote attacker to execute arbitrary code with the privileges of the FORM2RAW.exe process, potentially leading to full compromise of the mail server. At minimum, it can crash the component and disrupt mail processing.
Attack surface
The vulnerability is reached over the network via the Form2Raw.cgi interface by supplying an overly long From parameter. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and the attack is remotely reachable.
Exploitation
The record is not listed in CISA KEV, but EPSS is high at 0.65097 (99.2nd percentile) and multiple references are tagged Exploit, indicating public exploit information exists. No ransomware group usage is documented.
What to do
- Upgrade Alt-N MDaemon to a version later than 6.8.5 that addresses the FORM2RAW.exe overflow.
- If immediate upgrade is not possible, restrict network access to Form2Raw.cgi and the MDaemon web interface to trusted sources only.
- Disable or remove the Form2Raw.cgi component if it is not required for mail processing.
- Apply input length validation or a web application firewall rule to block oversized From parameters to Form2Raw.cgi.
- Monitor vendor advisories for MDaemon and apply any available hotfixes for the affected 6.5.2 through 6.8.5 range.
Detection
- Inspect web server and MDaemon logs for requests to Form2Raw.cgi with unusually long From parameter values.
- Monitor for crashes or abnormal process termination of FORM2RAW.exe on MDaemon hosts.
- Use network detection to alert on HTTP requests to Form2Raw.cgi containing long or malformed From fields.
- Correlate MDaemon host process creation events with unexpected child processes following Form2Raw.cgi activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://hat-squad.com/bugreport/mdaemon-raw.txt | |
| http://marc.info/?l=bugtraq&m=107936753929354&w=2 | |
| http://secunia.com/advisories/10512 | Vendor Advisory |
| http://www.osvdb.org/3255 | ExploitVendor Advisory |
| http://www.securityfocus.com/archive/1/348454 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/9317 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/14097 | |
| http://hat-squad.com/bugreport/mdaemon-raw.txt | |
| http://marc.info/?l=bugtraq&m=107936753929354&w=2 | |
| http://secunia.com/advisories/10512 | Vendor Advisory |
| http://www.osvdb.org/3255 | ExploitVendor Advisory |
| http://www.securityfocus.com/archive/1/348454 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/9317 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/14097 |
Track CVE-2003-1200 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-1200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.