Script Execution Vulnerability in Microsoft Exchange Outlook Web Access

A flaw exists in the interaction between Microsoft Exchange Server Outlook Web Access (OWA) and Microsoft Internet Explorer (IE) with message attachments.

Ken Pfeil

June 7, 2001

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported June 08, 2001, byMicrosoft.

VERSIONS AFFECTED

 

  • Microsoft Exchange 2000 Server using Outlook Web Access

  • Microsoft Exchange 5.5 Server using Outlook Web Access

  • Microsoft Internet Explorer

 

DESCRIPTION
Aflaw exists in the interaction between Microsoft Exchange Server Outlook WebAccess (OWA) and Microsoft Internet Explorer (IE) with message attachments. Ifan attachment contains HTML code that includes script, the script will executewhen the user opens the attachment, regardless of the attachment type. BecauseOWA requires that the user enable scripting in the zone where the OWA server islocated, this script can take action against the user’s Exchange mailbox as ifthe script were the user, including modifying and manipulating messages.

 

 

VENDOR RESPONSE

Thevendor, Microsoft, has acknowledged thisvulnerability and recommends that users immediately apply the patchmentioned in Security Bulletin MS01-030

 

CREDIT
Discovered by JoaoGouveia.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like