Microsoft Exchange Server vulnerabilities could allow remote code execution
Report ID: MS201212004
Date Published: 12 December 2012
Compromise Type: remote-code-execution denial-of-service
Compromise From: remote
Microsoft Exchange Server 2007
Microsoft Exchange Server is affected by multiple vulnerabilities that exposes an affected system to the risk of remote code execution and denial of service attack.
Microsoft has released a security update for Microsoft Exchange Server to address several vulnerabilities that could expose a machine to remote code execution and denial of service risk. Several vulnerabilities involve the Oracle Outside In libraries, and exist when the WebReady Document Viewer is used to preview a file. Another vulnerability was caused by improper handling of RSS feeds which could result in a denial of service condition.
The update fixes these issues by updating the affected Oracle Outside In libraries to a non-vulnerable version, and by correcting the way that RSS feeds are handled. Users are recommended to install the update onto their machine as a protection measure against possible exploit attempts.
Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms12-080)
F-Secure Health Check
F-Secure's free tool, the Health Check, detects if your system is missing the patch for the vulnerability covered in this report.