CERT-In Vulnerability Note
CIVN-2012-0116
Mutiple vulnerabilities in Microsoft Exchange Server
Original Issue Date:December 12, 2012
Severity Rating: HIGH
Systems Affected
- Microsoft Exchange Server 2007 Service Pack
- Microsoft Exchange Server 2010 Service Pack 1
- Microsoft Exchange Server 2010 Service Pack 2
Overview
Multiple vulnerabilities have been reported in Microsoft Exchange Server which could be exploited by remote attackers to cause denial of service conditions and arbitrary remote code execution .
Description
1. Microsoft Exchange Server RSS Feed processing Denial of Service Vulnerability
(
CVE-2012-4791
)
This vulnerability exists in Microsoft Exchange Server due to improper handling of RSS feeds . This Vulnerability could be exploited by an attacker by creating a crafted RSS feeds on the exchange server. Successful exploitation of this vulnerability could cause Exchange services unresponsive.The unresponsive state of the Exchange server could cause Exchange databases to dismount, results in database corruption and affect the mailboxes of the users.
2. Oracle Outside In Contains Multiple Exploitable Vulnerabilities
(
CVE-2012-3215CVE-2012-3217
)
This vulnerability exists in Web Ready Document Viewing feature of Microsoft Exchange Server .This Vulnerability could be exploited by remote attacker by creating a crafted file using Outlook Web App (OWA) and entices user to preview the file. Successful exploitation of this vulnerability could allow an attacker to run code on the affected server,but only as the Local Service account.
Workaround
- Disable Web Ready document view.
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS12-080
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-080
References
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-080
Security Tracker
http://securitytracker.com/id/1027857
http://securitytracker.com/id/1027669
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=27599
http://tools.cisco.com/security/center/viewAlert.x?alertId=27211
CVE Name
CVE-2012-4791
CVE-2012-3115
CVE-2012-3217
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|