I'm working on a robust answer to this....but meanwhile the direct answer is
that if you have Exchange exposed to the web....MS04-007 exploit properly
done can come right to that port and blow through it.
So, let's think about that. Build a port scanner, scan the web for any open
authenticating ports like 25, 80, 443, 1723 etc....fire away with the
exploit and the firewall never notices the server just fell over behind it.
Open port...no firewall involved.
The flaw here has specific interaction in authentication services. Almost a
worst case scenario. You can't even validate traffic without being killed by
it. It's a Knock, Knock joke that ends on the first K.