PT-2009-3989 · Mcafee+1 · Mcafee Groupshield+2

Publicado

2009-05-05

·

Atualizado

2017-08-17

·

CVE-2009-1491

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: McAfee GroupShield for Microsoft Exchange version on Exchange Server 2000
Description: The issue allows remote attackers to bypass virus detection by sending a crafted message. This is demonstrated by a message with an X-Testing header and no message body, which is not scanned for malicious content.
Recommendations: For McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, consider configuring the product to scan X- headers for malicious content as a temporary workaround until a patch is available. Restrict access to the email system to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1491

Produtos afetados

Exchange 2000 Server
Mcafee Groupshield
Exchange Server