PT-2009-2797 · Microsoft · Exchange Server
Publicado
2009-02-10
·
Atualizado
2018-10-12
·
CVE-2009-0098
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server versions 2000 SP3, 2003 SP2, 2007 SP1
Description
A remote code execution issue exists due to improper interpretation of Transport Neutral Encapsulation Format (TNEF) properties, allowing remote attackers to execute arbitrary code via a crafted TNEF message.
Recommendations
For Microsoft Exchange 2000 Server SP3, update to a version that properly handles TNEF properties to prevent code execution.
For Microsoft Exchange Server 2003 SP2, apply a fix that corrects the decoding of TNEF data to mitigate the risk of remote code execution.
For Microsoft Exchange Server 2007 SP1, modify the server configuration to correctly interpret TNEF properties and prevent arbitrary code execution.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Exchange Server