Microsoft Exchange Server Calendar Remote Code Execution Vulnerability
BID:17908
Info
Microsoft Exchange Server Calendar Remote Code Execution Vulnerability
| Bugtraq ID: | 17908 |
| Class: | Unknown |
| CVE: |
CVE-2006-0027 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2006 12:00AM |
| Updated: | Nov 15 2007 12:38AM |
| Credit: | The discoverer of this issue is not known. |
| Vulnerable: |
Microsoft Exchange Server 2003 SP2 Microsoft Exchange Server 2003 SP1 Microsoft Exchange Server 2003 Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange Server Calendar Remote Code Execution Vulnerability
Microsoft Exchange Server is prone to a vulnerability that may let attackers execute code remotely. This issue is exposed when the server handles emails that contain malicious calendar data that is included in meeting requests.
If the issue is successfully exploited, this could completely compromise the computer hosting the mail server.
Microsoft Exchange Server is prone to a vulnerability that may let attackers execute code remotely. This issue is exposed when the server handles emails that contain malicious calendar data that is included in meeting requests.
If the issue is successfully exploited, this could completely compromise the computer hosting the mail server.
Exploit / POC
Microsoft Exchange Server Calendar Remote Code Execution Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Exchange Server Calendar Remote Code Execution Vulnerability
Solution:
Microsoft has released a security bulletin to address supported versions of Microsoft Exchange Server.
Microsoft Exchange Server 2003 SP1
Microsoft Exchange Server 2003 SP2
Microsoft Exchange Server 2000
Solution:
Microsoft has released a security bulletin to address supported versions of Microsoft Exchange Server.
Microsoft Exchange Server 2003 SP1
-
Microsoft Security Update for Exchange Server 2003 SP1 (KB916803)
http://www.microsoft.com/downloads/details.aspx?familyid=F32574E0-F35C -4537-9AD0-524CB49AFE53&displaylang=en
Microsoft Exchange Server 2003 SP2
-
Microsoft Security Update for Exchange Server 2003 SP2 (KB916803)
http://www.microsoft.com/downloads/details.aspx?familyid=82AE4397-0982 -4585-84C1-DC1AF6944A0F&displaylang=en
Microsoft Exchange Server 2000
-
Microsoft Security Update for Exchange 2000 Server (KB916803)
For Microsoft Exchange Server 2000 with the Exchange 2000 Post-Service Pack 3 Update Rollup of August 2004.
http://www.microsoft.com/downloads/details.aspx?familyid=E72C8F94-782F -4670-9221-E2E37EADB8EC&displaylang=en
References
Microsoft Exchange Server Calendar Remote Code Execution Vulnerability
References:
References:
- Microsoft Security Bulletin MS06-019 (Microsoft)