CVE-1999-0682
Description
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Microsoft Exchange 5.5's anti-relay feature can be bypassed using encapsulated SMTP addresses, enabling remote spam relay.
Vulnerability
A remote attacker can bypass the anti-relaying protections in Microsoft Exchange Server 5.5 by using encapsulated SMTP addresses. Exchange Server 5.5, when configured as a gateway for other Exchange sites via the Internet Messaging Service, treats encapsulated SMTP addresses differently from standard SMTP addresses, allowing these addresses to circumvent the anti-relay restrictions. The vulnerability is present in all versions of Microsoft Exchange Server 5.5 prior to the patch referenced in [1].
Exploitation
An attacker with network access to an affected Exchange Server can send an email containing encapsulated SMTP addresses to the server. The server processes the encapsulated addresses and relays the email to the intended recipient, even if the anti-relaying features are enabled. No authentication is required; the attacker only needs to be able to connect to the server's SMTP port.
Impact
A successful exploitation allows the attacker to use the Exchange Server as an open mail relay, sending spam or malicious emails through the server. The server appears as the sender, which can lead to reputational damage, blacklisting, and potential disclosure of internal mail routing information. The confidentiality, integrity, and availability of the server are not directly compromised, but the server can be abused for mail relaying attacks.
Mitigation
Microsoft released a patch for Exchange Server 5.5 to address this vulnerability, as detailed in [1]. The patch makes encapsulated SMTP addresses subject to the same anti-relay protections as non-encapsulated SMTP addresses. Administrators should apply the patch from the August 1999 security bulletin or later updates. No workaround is mentioned in the reference. The vulnerability is not known to be listed on CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*
- Range: =5.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-027nvdPatchVendor Advisory
- www.securityfocus.com/bid/567nvdThird Party AdvisoryVDB Entry
- www.ciac.org/ciac/bulletins/j-056.shtmlnvdBroken Link
- support.microsoft.com/default.aspxnvd
News mentions
0No linked articles in our index yet.