- Recommend:
- 0 Comments
Exchange Server 5.5 Bug Could Be Exploited for Attacks
Patch has been available, but Microsoft didn't publicize it.
A vulnerability has been discovered in Microsoft's Exchange Server that would allow a single corrupt e-mail message to bring the server to its knees, and the software giant is recommending that users install an available patch.
The company issued a security bulletin on Tuesday saying the server has a denial-of-service vulnerability. The bug allows a malicious user to send an e-mail message with invalid data in the header that causes the Exchange Server to crash.
The vulnerability affects Exchange Server 5.5 but not Exchange 2000, which was released just last month. There are 58 million sets of Exchange in use today, according to Microsoft.
Microsoft is encouraging users to apply a patch available on its Web site. Users must be running Exchange with Service Pack 3 before they can install the patch. The fix will also be available in Service Pack 4, which is scheduled to ship before the end of the year.
According to an advisory sent out by Russ Cooper, who owns and moderates the NT BugTraq Internet discussion forum, it would be "pretty easy to keep an Exchange Server 5.5 site down if they haven't applied the patch."
Cooper says the simplicity of the malformed header means it could easily be discovered by hackers with malicious intent. A contributor to the NT BugTraq site reported the bug last week. Microsoft had already developed a patch but did not issue the security warning until Tuesday.
"There are no known attacks ongoing, nor have any happened that we're aware of," Cooper says in an e-mail message. "But the potential for such an attack makes me worried. It would be easy to send a malformed message to a spam list and get lots of folks."
In normal operation, Exchange checks for invalid values in the Multipurpose Internet Mail Extensions (MIME) header field of e-mail messages. If a particular type of value is present, the server fails, according to Microsoft. The server can regain normal operation only after a restart and deletion of the malicious e-mail message.
Cooper, who has tested the vulnerability, says it affects the Internet Mail Service in Exchange. When IMS tries to hand off the malicious message to the Information Store, the IMS fails and takes down Post Office Protocol 3 and Internet Messaging Access Protocol 4 services, according to Cooper. E-mail clients on the same network as the server, however, are still able to send and receive e-mail.
Microsoft says the vulnerability does not allow for the addition, deletion, or modification of e-mail messages stored in Exchange.
For more information about enterprise networking, go to NetworkWorld. Story copyright 2011 Network World Inc. All rights reserved.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Hosted Exchange Eliminates Server Admin Headaches
- Save With an Online Exchange Server
- Why Does the Letter 'J' Keep Appearing in My E-Mail Messages?
- Gmail's 'Bob' Features Help You Avoid E-mail Blunders
- Google Message Continuity Brings Gmail Benefits to Exchange
- Online Business Server Saves With Monthly Billing
- Volkswagen's After-Hours Blackberry E-mail Ban is a Brilliant Idea
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.



















