PT-2013-5796 · Microsoft+1 · Exchange Server 2007+4

Will Dormann

·

Publicado

2013-10-16

·

Atualizado

2018-10-12

·

CVE-2013-5791

CVSS v2.0

1.5

Baixa

VetorAV:L/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle Fusion Middleware versions 8.4.0 through 8.4.1 Exchange Server 2007 Exchange Server 2010 Exchange Server 2013
Description The issue allows attackers to affect availability and potentially execute arbitrary code. In the case of Exchange Server, vulnerabilities exist in the WebReady Document Viewing feature, which could allow remote code execution as the LocalService account if a user views a specially crafted file through Outlook Web Access in a browser. The LocalService account has minimum privileges on the local computer and presents anonymous credentials on the network.
Recommendations For Oracle Fusion Middleware versions 8.4.0 through 8.4.1, update to a version that addresses the issue in the Outside In Technology component. For Exchange Server 2007, Exchange Server 2010, and Exchange Server 2013, disable the WebReady Document Viewing feature until a patch is available to prevent remote code execution through specially crafted files. As a temporary workaround, consider restricting access to the WebReady Document Viewing feature in Exchange Server to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2013-5791

Produtos afetados

Exchange Server
Exchange Server 2007
Exchange Server 2010
Exchange Server 2013
Oracle Fusion Middleware