Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/7168 | vdb entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-049 | patch vendor advisory |
http://www.securityfocus.com/bid/3368 | vdb entry third party advisory |