Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
BID:9409
Info
Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
| Bugtraq ID: | 9409 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0904 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2004 12:00AM |
| Updated: | Jul 12 2009 02:06AM |
| Credit: | Announced by the vendor. |
| Vulnerable: |
Microsoft Exchange Server 2003 |
| Not Vulnerable: |
Microsoft Exchange Server 2000 SP3 Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
Discussion
Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
A vulnerability has been reported in Exchange Server 2003 with Outlook Web Access (OWA) configured. Exploitation of this vulnerability could allow an authenticated OWA user to connect to another user's OWA mailbox.
A vulnerability has been reported in Exchange Server 2003 with Outlook Web Access (OWA) configured. Exploitation of this vulnerability could allow an authenticated OWA user to connect to another user's OWA mailbox.
Exploit / POC
Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
Solution:
Microsoft has released an update to address this issue. Microsoft has reported that this security update cannot be detected by MBSA 1.1.1. As a result of this, SMS 2.0 Software Update Services Feature Pack and SMS 2.0 Administration Feature Pack's Elevated Rights Deployment Tool cannot be used for this security update.
Microsoft Exchange Server 2003
Solution:
Microsoft has released an update to address this issue. Microsoft has reported that this security update cannot be detected by MBSA 1.1.1. As a result of this, SMS 2.0 Software Update Services Feature Pack and SMS 2.0 Administration Feature Pack's Elevated Rights Deployment Tool cannot be used for this security update.
Microsoft Exchange Server 2003
-
Microsoft Security Update for Exchange 2003 (KB832759)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9542F949-D09B -4199-A837-FBCFC0567676&displaylang=en
References
Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
References:
References:
- Microsoft Security Bulletin MS04-002 (Microsoft)