VYPR
Unrated severityNVD Advisory· Published Aug 6, 1999· Updated Apr 16, 2026

CVE-1999-0682

CVE-1999-0682

Description

Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Microsoft Exchange 5.5's anti-relay feature can be bypassed using encapsulated SMTP addresses, enabling remote spam relay.

Vulnerability

A remote attacker can bypass the anti-relaying protections in Microsoft Exchange Server 5.5 by using encapsulated SMTP addresses. Exchange Server 5.5, when configured as a gateway for other Exchange sites via the Internet Messaging Service, treats encapsulated SMTP addresses differently from standard SMTP addresses, allowing these addresses to circumvent the anti-relay restrictions. The vulnerability is present in all versions of Microsoft Exchange Server 5.5 prior to the patch referenced in [1].

Exploitation

An attacker with network access to an affected Exchange Server can send an email containing encapsulated SMTP addresses to the server. The server processes the encapsulated addresses and relays the email to the intended recipient, even if the anti-relaying features are enabled. No authentication is required; the attacker only needs to be able to connect to the server's SMTP port.

Impact

A successful exploitation allows the attacker to use the Exchange Server as an open mail relay, sending spam or malicious emails through the server. The server appears as the sender, which can lead to reputational damage, blacklisting, and potential disclosure of internal mail routing information. The confidentiality, integrity, and availability of the server are not directly compromised, but the server can be abused for mail relaying attacks.

Mitigation

Microsoft released a patch for Exchange Server 5.5 to address this vulnerability, as detailed in [1]. The patch makes encapsulated SMTP addresses subject to the same anti-relay protections as non-encapsulated SMTP addresses. Administrators should apply the patch from the August 1999 security bulletin or later updates. No workaround is mentioned in the reference. The vulnerability is not known to be listed on CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*
  • Range: =5.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.