Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Exchange Server vulnerabilities could allow remote code execution


Report ID: MS201302004
Date Published: 22 February 2013

Criticality: Critical
Compromise Type: remote-code-execution denial-of-service
Compromise From: remote


Affected Product/Component:

Microsoft Exchange Server 2007
Microsoft Exchange Server 2010




Summary

Two vulnerabilities in Microsoft Exchange Server could lead to remote code execution and denial of service condition if successfully exploited.



Detailed Description

Microsoft has released a security update to address two reported vulnerabilities in Microsoft Exchange Server, concerning the WebReady Document Viewing feature that uses the Oracle Outside In libraries. Upon successful exploitation, the vulnerabilities could lead to arbitrary code execution or information disclosure.

Through the security update, the affected Oracle Outside In libraries has been updated to a non-vulnerable version. Users are recommended to get this latest update to protect their system from possible exploit attempts.



CVE Reference

CVE-2013-0393, CVE-2013-0418



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-012)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.