Microsoft Exchange Server vulnerabilities could allow remote code execution
Report ID: MS201302004
Date Published: 22 February 2013
Criticality: Critical
Compromise Type: remote-code-execution denial-of-service
Compromise From: remote
Affected Product/Component:
Microsoft Exchange Server 2007
Microsoft Exchange Server 2010
Summary
Two vulnerabilities in Microsoft Exchange Server could lead to remote code execution and denial of service condition if successfully exploited.
Detailed Description
Microsoft has released a security update to address two reported vulnerabilities in Microsoft Exchange Server, concerning the WebReady Document Viewing feature that uses the Oracle Outside In libraries. Upon successful exploitation, the vulnerabilities could lead to arbitrary code execution or information disclosure.
Through the security update, the affected Oracle Outside In libraries has been updated to a non-vulnerable version. Users are recommended to get this latest update to protect their system from possible exploit attempts.
CVE Reference
CVE-2013-0393, CVE-2013-0418
Solution
Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-012)
F-Secure Health Check
F-Secure's free tool, the Health Check, detects if your system is missing the patch for the vulnerability covered in this report.




