PT-2009-2797 · Microsoft · Exchange Server

Publicado

2009-02-10

·

Atualizado

2018-10-12

·

CVE-2009-0098

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server versions 2000 SP3, 2003 SP2, 2007 SP1
Description A remote code execution issue exists due to improper interpretation of Transport Neutral Encapsulation Format (TNEF) properties, allowing remote attackers to execute arbitrary code via a crafted TNEF message.
Recommendations For Microsoft Exchange 2000 Server SP3, update to a version that properly handles TNEF properties to prevent code execution. For Microsoft Exchange Server 2003 SP2, apply a fix that corrects the decoding of TNEF data to mitigate the risk of remote code execution. For Microsoft Exchange Server 2007 SP1, modify the server configuration to correctly interpret TNEF properties and prevent arbitrary code execution.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0098

Produtos afetados

Exchange Server