Security threats Toolkit
Story: Microsoft patches four critical IE, Exchange holes
Microsoft Exchange Patch
MS09-003 (Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution ) should also be looked at carefully. Microsoft Exchange handles sensitive and mission critical e-mail communication.
This vulnerability has the potential to be exploited by sending an e-mail:
The remote-code-execution vulnerability would allow any anonymous user to take full control over the exchange server and the system it resides on simply by sending a specially crafted e-mail.
A similar vulnerability in the past that involves TNEF.
http://www.microsoft.com/technet/security/bulletin/MS06-003.mspx It’s possible these are related.
The Exchange bulletin is a remote code executive, and as far as sensitive information and critical data are concerned, this has proven to be the easiest target for hackers to infiltrate. If the bad guys are able to compromise an organisation’s Exchange Server, then they will be able to intercept every email coming and going, essentially making it open to every corporation across the globe. Given the proximity of the Exchange Server to external data entering the network, organisations will want to deploy this update immediately. However, critical email services are often subject to change control processes that could make an urgent deployment a complex matter.
If this ends up being a Web-facing vulnerability, then it will be highly critical to patch as IT professionals constantly have to make sure these types of systems are patched and secure while running efficiently at the same time. Although the Exchange vulnerability is critical, organisations will want to read the details of the patch carefully in case there are any mitigating controls.
lumension
LONDON, UK
Member since: October 2008
Site Activity Rating:
This member is ranked #84 in our top 100
Full Talkback thread








