CERT-In Vulnerability Note
CIVN-2014-0274
Multiple Vulnerabilities in Microsoft Exchange Server
Original Issue Date:December 10, 2014
Severity Rating: MEDIUM
Systems Affected
- Microsoft Exchange Server 2007 SP3
- Microsoft Exchange Server 2010 SP3
- Microsoft Exchange Server 2013 SP
- Microsoft Exchange Server 2013 Cumulative Update 6
Overview
Multiple Vulnerabilities have been reported in Microsoft Exchange Server which could allow a remote attacker to gain elevated privileges on the targeted system.
Description
1. Outlook Token Spoofing Vulnerability
(
CVE-2014-6319
)
This vulnerability exists in the Outlook Web Access App (OWA) in Microsoft Exchange Server due to improper processing of a request token. A remote attacker could exploit this vulnerability by enticing the user to open a specially crafted link containing a malicious content. Successful exploitation of this vulnerability could allow a remote attacker to send spoofed email messages to targeted user.
2. Cross Site Scripting Vulnerabilities
(
CVE-2014-6325
CVE-2014-6326
)
These vulnerabilities exist in the Outlook Web Access in Microsoft Exchange Server due to improper validation of input. A remote attacker could exploit these vulnerabilities by enticing the targeted user to view a malicious URL within Outlook Web Access. Successful exploitation of these vulnerabilities could allow the attacker to run arbitrary script in the context of the targeted user.
3. URL Redirection Spoofing Vulnerability
(
CVE-2014-6336
)
This vulnerability exists in the Outlook Web Access App (OWA) in Microsoft Exchange Server due to improper validation of redirection tokens. A remote, authenticated attacker could exploit this vulnerability by enticing a user to visit the link in the email message which could allow the attacker to conduct spoofing attacks.
Workaround
- Exercise caution while opening attachments received in email from unknown or untrusted sources
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS14-075
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/ms14-075
References
Microsoft
https://technet.microsoft.com/library/security/ms14-075
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36596
http://tools.cisco.com/security/center/viewAlert.x?alertId=36598
http://tools.cisco.com/security/center/viewAlert.x?alertId=36597
Security Focus
http://www.securityfocus.com/bid/65934
http://www.securityfocus.com/bid/71440
http://www.securityfocus.com/bid/71441
http://www.securityfocus.com/bid/71443
CVE Name
CVE-2014-6325
CVE-2014-6319
CVE-2014-6326
CVE-2014-6336
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|