Trend Micro ScanMail For Exchange Authentication Bypass Vulnerability
BID:6619
Info
Trend Micro ScanMail For Exchange Authentication Bypass Vulnerability
| Bugtraq ID: | 6619 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2003 12:00AM |
| Updated: | Jan 15 2003 12:00AM |
| Credit: | Rod Boron <[email protected]> reported this vulnerability. |
| Vulnerable: |
Trend Micro ScanMail for Microsoft Exchange 3.8 |
| Not Vulnerable: |
Trend Micro ScanMail for Microsoft Exchange 6.1 Trend Micro ScanMail for Microsoft Exchange 3.81 |
Discussion
Trend Micro ScanMail For Exchange Authentication Bypass Vulnerability
A vulnerability has been reported for ScanMail for Microsoft Exchange. The vulnerability allows a remote attacker to bypass existing authentication mechanisms and obtain access to ScanMail's management system.
A vulnerability has been reported for ScanMail for Microsoft Exchange. The vulnerability allows a remote attacker to bypass existing authentication mechanisms and obtain access to ScanMail's management system.
Exploit / POC
Trend Micro ScanMail For Exchange Authentication Bypass Vulnerability
The following proof of concept was provided:
http://x.x.x.x:16372/smg_Smxcfg30.exe?vcc=3560121183d3
The following proof of concept was provided:
http://x.x.x.x:16372/smg_Smxcfg30.exe?vcc=3560121183d3
Solution / Fix
Trend Micro ScanMail For Exchange Authentication Bypass Vulnerability
Solution:
This issue is addressed in ScanMail for Microsoft Exchange versions 3.81/6.1 and later. Users are advised to upgrade.
Solution:
This issue is addressed in ScanMail for Microsoft Exchange versions 3.81/6.1 and later. Users are advised to upgrade.
References
Trend Micro ScanMail For Exchange Authentication Bypass Vulnerability
References:
References:
- Solution 13352 (Trend Micro)
- Trend Micro Homepage (Trend Micro)