Advertisement
Promo

Security threats Toolkit

Story: Microsoft patches four critical IE, Exchange holes

  • Previous comment

Posted by: lumension (Monday 16 February 2009, 12:53 PM)

  • Reply

Microsoft Exchange Patch

MS09-003 (Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution ) should also be looked at carefully. Microsoft Exchange handles sensitive and mission critical e-mail communication.

This vulnerability has the potential to be exploited by sending an e-mail:

The remote-code-execution vulnerability would allow any anonymous user to take full control over the exchange server and the system it resides on simply by sending a specially crafted e-mail.

A similar vulnerability in the past that involves TNEF.
http://www.microsoft.com/technet/security/bulletin/MS06-003.mspx It’s possible these are related.

The Exchange bulletin is a remote code executive, and as far as sensitive information and critical data are concerned, this has proven to be the easiest target for hackers to infiltrate. If the bad guys are able to compromise an organisation’s Exchange Server, then they will be able to intercept every email coming and going, essentially making it open to every corporation across the globe. Given the proximity of the Exchange Server to external data entering the network, organisations will want to deploy this update immediately. However, critical email services are often subject to change control processes that could make an urgent deployment a complex matter.

If this ends up being a Web-facing vulnerability, then it will be highly critical to patch as IT professionals constantly have to make sure these types of systems are patched and secure while running efficiently at the same time. Although the Exchange vulnerability is critical, organisations will want to read the details of the patch carefully in case there are any mitigating controls.

Private message disabled

lumension

lumension
LONDON, UK
Member since: October 2008

Site Activity Rating:

3

This member is ranked #84 in our top 100


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters