Microsoft Exchange OWA Embedded Script Execution Vulnerability
BID:2832
Info
Microsoft Exchange OWA Embedded Script Execution Vulnerability
| Bugtraq ID: | 2832 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2001 12:00AM |
| Updated: | Jun 06 2001 12:00AM |
| Credit: | Discovered by Joao Gouveia <[email protected]> and posted in a Microsoft Security Bulletin MS01-030 on June 6, 2001. |
| Vulnerable: |
Microsoft Exchange Server 2000 Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange OWA Embedded Script Execution Vulnerability
Outlook Web Access ships with Microsoft Exchange 2000 by default.
Because of a flaw in the interaction between Outlook Web Access (OWA) and Internet Explorer, it is possible for an email attachment to be executed without prompting the user first.
If an email attachment is received by a user (using OWA and IE to retrieve mail), the attachment could be executed without prompting the user with a dialogue requesting the selection of the appropriate application to view the file. Therefore, an HTML attachment containing a script will run without the user's knowledge.
Outlook Web Access ships with Microsoft Exchange 2000 by default.
Because of a flaw in the interaction between Outlook Web Access (OWA) and Internet Explorer, it is possible for an email attachment to be executed without prompting the user first.
If an email attachment is received by a user (using OWA and IE to retrieve mail), the attachment could be executed without prompting the user with a dialogue requesting the selection of the appropriate application to view the file. Therefore, an HTML attachment containing a script will run without the user's knowledge.
Exploit / POC
Microsoft Exchange OWA Embedded Script Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Exchange OWA Embedded Script Execution Vulnerability
Solution:
On June 8, 2001 a regression error was found in Microsoft's original patch released for Exchange 2000. On June 12, 2001, Microsoft discovered that the previously released patch for Exchange 2000 contained outdated files. They have re-released the Exchange 2000 patch and encourage user's to install the updated one.
Microsoft Exchange Server 5.5 SP1
Microsoft Exchange Server 5.5 SP3
Microsoft Exchange Server 5.5 SP4
Microsoft Exchange Server 5.5 SP2
Microsoft Exchange Server 5.5
Microsoft Exchange Server 2000
Solution:
On June 8, 2001 a regression error was found in Microsoft's original patch released for Exchange 2000. On June 12, 2001, Microsoft discovered that the previously released patch for Exchange 2000 contained outdated files. They have re-released the Exchange 2000 patch and encourage user's to install the updated one.
Microsoft Exchange Server 5.5 SP1
-
Microsoft Q301361
http://download.microsoft.com/download/exch55/Patch/05.05.12.2655/NT45 /EN-US/Q301361i386.EXE
Microsoft Exchange Server 5.5 SP3
-
Microsoft Q301361
http://download.microsoft.com/download/exch55/Patch/05.05.12.2655/NT45 /EN-US/Q301361i386.EXE
Microsoft Exchange Server 5.5 SP4
-
Microsoft Q301361
http://download.microsoft.com/download/exch55/Patch/05.05.12.2655/NT45 /EN-US/Q301361i386.EXE
Microsoft Exchange Server 5.5 SP2
-
Microsoft Q301361
http://download.microsoft.com/download/exch55/Patch/05.05.12.2655/NT45 /EN-US/Q301361i386.EXE
Microsoft Exchange Server 5.5
-
Microsoft Q301361
http://download.microsoft.com/download/exch55/Patch/05.05.12.2655/NT45 /EN-US/Q301361i386.EXE
Microsoft Exchange Server 2000
References
Microsoft Exchange OWA Embedded Script Execution Vulnerability
References:
References:
- Microsoft Security Bulletin MS01-030 (Microsoft)