---
id: CVE-1999-0203
title: >-
  In Sendmail, attackers can gain root privileges via SMTP by specifying an
  improper "mail from" address and an invalid "rcpt to" address that would cause
  the mail to bounce to a program.
summary: >-
  In Sendmail, attackers can gain root privileges via SMTP by specifying an
  improper "mail from" address and an invalid "rcpt to" address that would cause
  the mail to bounce to a program.
severity: critical
cvss: 10
cvssVector: 'AV:N/AC:L/Au:N/C:C/I:C/A:C'
published: '1995-08-17'
updated: '2026-06-16'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-1999-0203'
references:
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0203'
    label: cve@mitre.org
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0203'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02124
epssPercentile: 0.81122
ingestedAt: '2026-06-19T03:39:00.757Z'
---

## Overview

In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
