Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Exchange Server vulnerabilities could allow remote code execution


Report ID: MS201212004
Date Published: 12 December 2012

Criticality: Critical
Compromise Type: remote-code-execution denial-of-service
Compromise From: remote


Affected Product/Component:

Microsoft Exchange Server 2007




Summary

Microsoft Exchange Server is affected by multiple vulnerabilities that exposes an affected system to the risk of remote code execution and denial of service attack. 



Detailed Description

Microsoft has released a security update for Microsoft Exchange Server to address several vulnerabilities that could expose a machine to remote code execution and denial of service risk. Several vulnerabilities involve the Oracle Outside In libraries, and exist when the WebReady Document Viewer is used to preview a file. Another vulnerability was caused by improper handling of RSS feeds which could result in a denial of service condition.

The update fixes these issues by updating the affected Oracle Outside In libraries to a non-vulnerable version, and by correcting the way that RSS feeds are handled. Users are recommended to install the update onto their machine as a protection measure against possible exploit attempts.  



CVE Reference

CVE-2012-4791



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms12-080)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.