Vulnerability record · CVE-2005-0560 · published 2 May 2005
CVE-2005-0560: Microsoft Exchange SMTP Service Heap Buffer Overflow via X-LINK2STATE Verb
Microsoft · Exchange Server
The SvrAppendReceivedChunk function in xlsasink.dll in the Exchange Server 2000 and 2003 SMTP service contains a heap-based buffer overflow. A remote attacker can trigger it by sending a crafted X-LINK2STATE extended verb request to the SMTP port, potentially executing arbitrary code in the SMTP service context.
Description
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution in a widely deployed mail service with a very high EPSS score, though no KEV listing or documented ransomware use.
What it is
The SvrAppendReceivedChunk function in xlsasink.dll in the Exchange Server 2000 and 2003 SMTP service contains a heap-based buffer overflow. A remote attacker can trigger it by sending a crafted X-LINK2STATE extended verb request to the SMTP port, potentially executing arbitrary code in the SMTP service context.
Impact
Successful exploitation allows remote code execution with the privileges of the Exchange SMTP service, which typically runs as SYSTEM on the host. This can lead to full compromise of the mail server and any data or credentials it handles.
Attack surface
Reachable over the network via the SMTP port (TCP 25) using the X-LINK2STATE extended verb; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.69482, 99.3rd percentile), indicating elevated likelihood of exploitation activity. References include vendor and US-CERT patch advisories, but no public exploit tag is present in the record.
What to do
- Apply the Microsoft security update for MS05-021 (Exchange Server 2000 and 2003) immediately.
- If patching cannot be done at once, disable or block the X-LINK2STATE extended verb on the SMTP service.
- Restrict inbound SMTP (TCP 25) to trusted mail relays and gateways only.
- Run the Exchange SMTP service with least privilege where operationally feasible, and monitor for unexpected service restarts or crashes.
- Review Exchange server logs for anomalous X-LINK2STATE commands and treat them as suspicious.
Detection
- Inspect SMTP protocol logs and packet captures for X-LINK2STATE extended verb usage, especially from untrusted external hosts.
- Monitor Exchange SMTP service (xlsasink.dll) for crashes, restarts, or abnormal memory-related events.
- Alert on unexpected outbound connections or process creation originating from the Exchange SMTP service process.
- Correlate SMTP traffic anomalies with host-based indicators such as new files or registry changes on the Exchange server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0560 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0560), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.