Microsoft Exchange Server under major security risk
On the face of it, Microsoft’s latest monthly update seems quite light with ‘just’ two critical vulnerabilities. But one of them, for Exchange Server, is an absolute doozy.
The issue, which affects the 2000, 2003 and 2007 editions, means that a hacker could take complete control of a system – with administrative privileges – simply by sending a specially crafted message with a rogue winmail.dat file, the attachment which tells e-mail programs how to display a Rich Text Format document. To make things worse, the problem could affect users who simply preview the message without having to open it.
The vulnerability is understandably rated critical, though Microsoft’s separate exploitability index gives it a medium rating for the likelihood of hackers taking advantage. That’s a fairly arbitrary rating based on the fact that there’s no evidence the hacking community has figured out how to exploit the issue yet.