Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
BID:33136
Info
Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
| Bugtraq ID: | 33136 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-0099 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2009 12:00AM |
| Updated: | Feb 17 2009 03:48PM |
| Credit: | Bogdan Materna of VoIPshield Systems |
| Vulnerable: |
Microsoft Exchange Server MAPI Client 1.2.1 Microsoft Exchange Server 2003 SP2 Microsoft Exchange Server 2003 SP1 Microsoft Exchange Server 2003 Microsoft Exchange Server 2000 SP3 Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
Microsoft Exchange Server is prone to a remote denial-of-service vulnerability.
A successful exploit allows a remote attacker to cause the application to stop responding, denying service to legitimate users.
Microsoft Exchange Server is prone to a remote denial-of-service vulnerability.
A successful exploit allows a remote attacker to cause the application to stop responding, denying service to legitimate users.
Exploit / POC
Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
Solution:
Fixes are available; please see the references for more information.
Microsoft Exchange Server 2000 SP3
Microsoft Exchange Server 2003 SP2
Microsoft Exchange Server MAPI Client 1.2.1
Solution:
Fixes are available; please see the references for more information.
Microsoft Exchange Server 2000 SP3
-
Microsoft Security Update for Exchange 2000 Server (KB959897)
http://www.microsoft.com/downloads/details.aspx?familyid=805dc856-ea60 -477d-be40-6ac535a7e7e5
Microsoft Exchange Server 2003 SP2
-
Microsoft Security Update for Exchange Server 2003 Service Pack 2 (KB959897)
http://www.microsoft.com/downloads/details.aspx?familyid=1d9f0956-88bd -4e13-a86b-b1c8d4782f71
Microsoft Exchange Server MAPI Client 1.2.1
-
Microsoft Microsoft Exchange Server MAPI Client and Collaboration Data Objects 1.2.1
http://www.microsoft.com/downloads/details.aspx?FamilyID=E17E7F31-079A -43A9-BFF2-0A110307611E&displaylang=en
References
Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
References:
References:
- Avaya Security Advisory ASA-2009-054 (Avaya)
- Exchange Server Home Page (Microsoft)
- Microsoft Knowledge Base Article 959239 (Microsoft)
- Microsoft Security Bulletin MS09-003 (Microsoft)