Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
| Software | From | Fixed in |
|---|---|---|
| microsoft / exchange_server | 2000-sp3 | 2000-sp3.x |
| microsoft / windows_server_2003 | r2 | r2.x |
| microsoft / windows_server_2003 | sp1 | sp1.x |
| microsoft / windows_2000 | --sp4 | --sp4.x |
| microsoft / windows_xp | --sp1 | --sp1.x |
| microsoft / windows_xp | --sp2 | --sp2.x |