Microsoft released a critical patch for Exchange 2000 and 2003 yesterday. This could be very serious as it looks like it can be exploited with an SMTP message to an effected server. I would suggest that you test and deploy this patch as soon as you can.
Details:
This is a remote code execution vulnerability. An attacker who successfully exploited this vulnerability could remotely take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
- Joel