Microsoft Outlook Web Access Denial of Service Vulnerability
BID:3223
Info
Microsoft Outlook Web Access Denial of Service Vulnerability
| Bugtraq ID: | 3223 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2001 12:00AM |
| Updated: | Aug 22 2001 12:00AM |
| Credit: | This vulnerability was originally reported by Andrew McQueen <[email protected]> |
| Vulnerable: |
Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Web Access Denial of Service Vulnerability
Outlook Web Access is an optional component of Microsoft Exchange Server which runs in conjunction with Microsoft Internet Information Server. It provides access to a user's Exchange mailbox through a web interface.
A user can enter a long string of % characters into the Log On field in the Outlook Web Access page. Then, when the user receives the NT challenge dialog, a username and password composed of a long string of % characters is also entered. This will cause the WWW Publishing service and the IIS Administration service to stop.
Note: If this behaviour is due to a buffer overrun condition, it may be possible to execute arbitrary code on the server with administrative privileges.
Outlook Web Access is an optional component of Microsoft Exchange Server which runs in conjunction with Microsoft Internet Information Server. It provides access to a user's Exchange mailbox through a web interface.
A user can enter a long string of % characters into the Log On field in the Outlook Web Access page. Then, when the user receives the NT challenge dialog, a username and password composed of a long string of % characters is also entered. This will cause the WWW Publishing service and the IIS Administration service to stop.
Note: If this behaviour is due to a buffer overrun condition, it may be possible to execute arbitrary code on the server with administrative privileges.
Exploit / POC
Microsoft Outlook Web Access Denial of Service Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Microsoft Outlook Web Access Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.