PT-2012-5593 · Microsoft · Exchange Server
Published
2012-12-11
·
Updated
2019-06-01
·
CVE-2012-4791
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server versions 2007 SP3 through 2010 SP2
Description
A denial of service issue exists due to improper handling of RSS feeds, which could cause the Information Store service to become unresponsive. This condition may lead to Exchange databases dismounting and potentially result in database corruption, affecting user mailboxes.
Recommendations
For Microsoft Exchange Server versions 2007 SP3 through 2010 SP2, consider disabling the RSS feed subscription feature as a temporary workaround until a patch is available. Restrict access to crafted RSS feeds to minimize the risk of exploitation.
Fix
DoS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server