Skip to main content

Microsoft Exchange Server Multiple Vulnerabilities

Last Update Date: 15 Aug 2012 16:59 Release Date: 15 Aug 2012 3758 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Remote code execution vulnerabilities exist in Microsoft Exchange Server through the WebReady Document Viewing feature. These vulnerabilities could allow remote code execution as Local System if a user views a specially crafted file through Outlook Web Access in a browser. An attacker who successfully exploited the vulnerabilities could run code on the affected server, but only as LocalService. The LocalService account has minimum privileges on the local computer and presents anonymous credentials on the network.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Exchange Server 2007
  • Microsoft Exchange Server 2010

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link