CVE-2017-6506: Azure Dex Data Expert Ultimate

Critical severity, CVSS 9.8. EPSS: 11.7% chance of exploitation in the next 30 days.

In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.

Affected products

  • Azure Dex Data Expert Ultimate: version 2.2.16 only

Published 2017-03-10. Last modified 2026-06-17.