Become a Columnist Microsoft Exchange Site Microsoft Support SiteMSDN Exchange Site
Subscribe to OutlookExchange
Anderson Patricio
Ann Mc Donough
Bob Spurzem
Brian Veal
Catherine Creary
Cherry Beado
Colin Janssen
Collins Timothy Mutesaria
Drew Nicholson
Fred Volking
Glen Scales
Goran Husman
Guy Thomas
Henrik Walther
Jason Sherry
Jayme Bowers
John Young
Joyce Tang
Justin Braun
Konstantin Zheludev
Kristina Waters
Kuang Zhang
Mahmoud Magdy
Martin Tuip
Michael Dong
Michele Deo
Mitch Tulloch
Nicolas Blank
Pavel Nagaev
Ragnar Harper
Ricardo Silva
Richard Wakeman
Russ Iuliano
Santhosh Hanumanthappa
Shannal L. Thomas
Steve Bryant
Steve Craig
Todd Walker
Tracey J. Rosenblath

 

 
  Joyce Tang's Column

:: J o y c e T a n g ' s C o l u m n ::

>> Outlook Web Access Script Execution Vulnerability in Microsoft Server 5.5
Dec 2001

A vulnerability exists in the Microsoft Exchange Server 5.5 Outlook Web Access (OWA) service that lets an attacker take any action on the user’s mailbox that the user can take, including deleting, moving and sending messages. The way OWA handles inline script message used in conjunction with Internet Explorer (IE) created a loophole for malicious users. The attacker is able to execute scripts that allow the attacker access to the user's mailbox. Prior to the released patch, OWA does not filter out scripts embedded in the message, the patch corrects this problem by stripping the scripts before sending it to IE.

This vulnerability only affects OWA used with IE and such scripts will not work on Outlook client or Outlook Express. Non-IE browsers are also not affected, according to Microsoft.

Lex Arquette of WhiteHat Security is credited for reporting this issue to Microsoft.

For more details, go to Microsoft Security Bulletin MS01-057.

For patches, go to Exchange 5.5 Web Client Hotfix 2655.77

 

Did you find this article useful? Do you want to see more of this kind or something else? I would really appreciate your comments, feel free to email me!

<< go back my previous article about Outlook Synchronization for Offline Users

<< go back my main page

<< go back to outlookexchange.com

 

 

 

Welcome to Outlook Exchange
Become a Columnist Microsoft Exchange Site Microsoft Support SiteMSDN Exchange Site
Subscribe to OutlookExchange
Anderson Patricio
Ann Mc Donough
Bob Spurzem
Brian Veal
Catherine Creary
Cherry Beado
Colin Janssen
Collins Timothy Mutesaria
Drew Nicholson
Fred Volking
Glen Scales
Goran Husman
Guy Thomas
Henrik Walther
Jason Sherry
Jayme Bowers
John Young
Joyce Tang
Justin Braun
Konstantin Zheludev
Kristina Waters
Kuang Zhang
Mahmoud Magdy
Martin Tuip
Michael Dong
Michele Deo
Mitch Tulloch
Nicolas Blank
Pavel Nagaev
Ragnar Harper
Ricardo Silva
Richard Wakeman
Russ Iuliano
Santhosh Hanumanthappa
Shannal L. Thomas
Steve Bryant
Steve Craig
Todd Walker
Tracey J. Rosenblath