CVE-2005-0738

MEDIUM

Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Mic...

Affects 1 product across 1 vendor.

BCS4.88
CVSS 2.05.0
EPSS4.5%
Percentile91th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no confidentiality impact, no integrity impact.
CWE Weakness Definitions
CWE-400: Uncontrolled Resource Consumption (DoS)

Software does not properly limit resource usage, allowing an attacker to exhaust CPU, memory, disk, or bandwidth.

Related Attack Patterns (CAPEC)
CAPEC-147 XML Ping of the Death
via CWE-400
CAPEC-492 Regular Expression Exponential Blowup
via CWE-400
CAPEC-227 Sustained Client Engagement
via CWE-400

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2005. A medium severity vulnerability affects Microsoft systems (CVE-2005-0738). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2005-GLOBAL-009554-M • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2005-0738?
This vulnerability was disclosed in 2005. A medium severity vulnerability affects Microsoft systems (CVE-2005-0738). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2005-0738?
CVE-2005-0738 has CVSS 5.0 (Medium). Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P. EPSS: 4.5%.
Is CVE-2005-0738 actively exploited?
No confirmed active exploitation of CVE-2005-0738 as of 2026-05-30.
How do I remediate CVE-2005-0738?
Priority: MONITOR. Advisory: http://support.microsoft.com/?kbid=891504 PSIRT: [email protected]
What systems are affected by CVE-2005-0738?
CVE-2005-0738 affects: Microsoft.
Vulnerability Details
CVE IDCVE-2005-0738
BSIDBS-2005-GLOBAL-009554-M BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Published2005-05-02
Last Modified2026-04-16
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls. CVSS vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Microsoft Exchange Server
Remediation
View Vendor Advisory →

Remediation Priority: MONITOR

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 7754 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashbaf7e4b475ab3a1c1211aed6e21ce6b0e4285e5a0652766e08f2a7330c6ed709fbec1c11d242e313db591e67ce963325bfde217378039177e55051f587bc87de
Related CVEs affecting Microsoft
CVE-2000-0222 10.0 The installation for Windows 2000 does not activate the Administrator passwor... CVE-2001-0147 10.0 Buffer overflow in Windows 2000 event viewer snap-in allows attackers to exec... CVE-2001-0538 10.0 Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier ... CVE-1999-0535 10.0 A Windows NT account policy for passwords has inappropriate, security-critica... CVE-1999-0385 10.0 The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a re...
View all Microsoft CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →