CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS13-105 | Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (2915705) | Microsoft Exchange | Critical | 11-12-2013 |
Technical Information
Brief overview of the risk:
This security update resolves three publicly disclosed vulnerabilities and one privately reported vulnerability in Microsoft Exchange Server. The most severe of these vulnerabilities exist in the WebReady Document Viewing and Data Loss Prevention features of Microsoft Exchange Server. These vulnerabilities could allow remote code execution in the security context of the LocalService account if an attacker sends an email message containing a specially crafted file to a user on an affected Exchange server. The LocalService account has minimum privileges on the local system and presents anonymous credentials on the network.
Detailed Information on the risk:
A remote code execution vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the Outlook Web Access (OWA) service account.
Further information on this exploit is available at : MS13-105
Affected Software
Microsoft Exchange Server 2007 Service Pack 3Microsoft Exchange Server 2010 Service Pack 2
Microsoft Exchange Server 2010 Service Pack 3
Microsoft Exchange Server 2013 Cumulative Update 2
Microsoft Exchange Server 2013 Cumulative Update 3