← Vulnerability feed

Vulnerability record · CVE-2003-1200 · published 29 December 2003

CVE-2003-1200: Alt-N MDaemon FORM2RAW.exe stack buffer overflow via From parameter

AAlt N · Mdaemon

FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 contains a stack-based buffer overflow reachable through a long From parameter passed to Form2Raw.cgi. A remote attacker can overwrite stack memory and potentially execute arbitrary code on the mail server. The flaw affects an unauthenticated network-reachable component, making it a serious pre-auth risk for exposed MDaemon installations.

7.5 CVSS 2.0 High EPSS 65% · top 0.8%
7.5CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution in an internet-facing mail component with public exploit references and very high EPSS, though no KEV listing or confirmed in-the-wild ransomware use.

What it is

FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 contains a stack-based buffer overflow reachable through a long From parameter passed to Form2Raw.cgi. A remote attacker can overwrite stack memory and potentially execute arbitrary code on the mail server. The flaw affects an unauthenticated network-reachable component, making it a serious pre-auth risk for exposed MDaemon installations.

Impact

Successful exploitation can allow a remote attacker to execute arbitrary code with the privileges of the FORM2RAW.exe process, potentially leading to full compromise of the mail server. At minimum, it can crash the component and disrupt mail processing.

Attack surface

The vulnerability is reached over the network via the Form2Raw.cgi interface by supplying an overly long From parameter. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and the attack is remotely reachable.

Exploitation

The record is not listed in CISA KEV, but EPSS is high at 0.65097 (99.2nd percentile) and multiple references are tagged Exploit, indicating public exploit information exists. No ransomware group usage is documented.

What to do

  • Upgrade Alt-N MDaemon to a version later than 6.8.5 that addresses the FORM2RAW.exe overflow.
  • If immediate upgrade is not possible, restrict network access to Form2Raw.cgi and the MDaemon web interface to trusted sources only.
  • Disable or remove the Form2Raw.cgi component if it is not required for mail processing.
  • Apply input length validation or a web application firewall rule to block oversized From parameters to Form2Raw.cgi.
  • Monitor vendor advisories for MDaemon and apply any available hotfixes for the affected 6.5.2 through 6.8.5 range.

Detection

  • Inspect web server and MDaemon logs for requests to Form2Raw.cgi with unusually long From parameter values.
  • Monitor for crashes or abnormal process termination of FORM2RAW.exe on MDaemon hosts.
  • Use network detection to alert on HTTP requests to Form2Raw.cgi containing long or malformed From fields.
  • Correlate MDaemon host process creation events with unexpected child processes following Form2Raw.cgi activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-1200 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-5709Alt-n mdaemon vulnerabilityUnspecified vulnerability in WorldClient in Alt-N Technologies MDaemon before 9.50 has unknown impact and attack vectors related to a "JavaScript exp…EPSS 1.6%9.0CVE-2003-1470Alt-n mdaemon memory buffer overflow vulnerabilityBuffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbit…EPSS 5.0%7.5CVE-2006-5708Alt-n mdaemon uncontrolled resource consumption vulnerabilityMultiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of servic…EPSS 1.0%7.5CVE-2006-2646Alt-n mdaemon vulnerabilityBuffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins…EPSS 4.6%7.5CVE-2005-4266Alt-n mdaemon vulnerabilityWorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated wi…EPSS 1.3%7.5CVE-2000-1020Alt-n mdaemon vulnerabilityHeap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary command…EPSS 2.3%7.5CVE-2000-1021Alt-n mdaemon vulnerabilityHeap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands …EPSS 3.8%7.2CVE-2004-2504Alt-n mdaemon vulnerabilityThe GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users …EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2003-1200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.