CVE-2002-1876 describes a denial-of-service vulnerability in Microsoft Exchange 2000. Authenticated attackers can exhaust IIS licenses by sending a high volume of rapid requests, rendering the service unavailable. This vulnerability has a low CVSS score of 2.1, indicating a low impact potential, and requires local access for exploitation. There is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code, despite a notable level of community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2000:-:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2000:sp1:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2000:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.