CyberSec.Space Logo
Back to CVE Browser

CVE-2004-0840

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1100%
EPSS Percentile4.49th
PublishedNov 3, 2004
Last ModifiedApr 16, 2026

Vulnerability Description

The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.

Affected Platforms (CPE)

πŸ“¦
Microsoft

Exchange Server

= 2003
πŸ’»
Microsoft

Windows Server 2003

All versions
πŸ’»
Microsoft

Windows Server 2003

= r2
πŸ’»
Microsoft

Windows Xp

All versions

References & Advisories

Related Vulnerabilities