Skip to main content

Microsoft Exchange Server under major security risk

posted onFebruary 12, 2009
by hitbsecnews

On the face of it, Microsoft’s latest monthly update seems quite light with ‘just’ two critical vulnerabilities. But one of them, for Exchange Server, is an absolute doozy.

The issue, which affects the 2000, 2003 and 2007 editions, means that a hacker could take complete control of a system – with administrative privileges – simply by sending a specially crafted message with a rogue winmail.dat file, the attachment which tells e-mail programs how to display a Rich Text Format document. To make things worse, the problem could affect users who simply preview the message without having to open it.

The vulnerability is understandably rated critical, though Microsoft’s separate exploitability index gives it a medium rating for the likelihood of hackers taking advantage. That’s a fairly arbitrary rating based on the fact that there’s no evidence the hacking community has figured out how to exploit the issue yet.

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th