A Patch Begets a Patch...Begets Another Patch?

Microsoft Corp. Wednesday rereleased -- again -- the patch for a recent exploit in Outlook Web Access (OWA), a Web-based interface for a Microsoft Exchange Server 5.5 and Exchange Server 2000.

Our story thus far: On Wednesday, June 6, Microsoft released version 1.0 of a software patch to fix an exploit in OWA. In a bulletin ( published on its Security Web site, Microsoft itself recommended that users who rolled-out OWA - i.e., most Exchange 5.5 and Exchange 2000 deployments - should "install the patch immediately."

Fast forward two days: On Friday, June 8, the OWA security update disappeared temporarily from Microsoft's "Download" Web site, replaced by a cryptic message which indicated that the patch was "temporarily unavailable" but which promised that it would "be returned to the Web shortly." The day before, Thursday, June 5, at least two users posted messages to the Windows NT Systems Administrators mailing list ( in which they complained that the patch caused their Exchange servers to crash shortly after they installed it. Coincidence?

Apparently not. On Saturday, Microsoft confirmed that version 1.0 of the OWA patch was flawed - according to a revision notice that was appended to the original security bulletin, the likely culprit was identified as a "regression" error - and issued a new 2.0 version of the update that had (ostensibly) been tested and certified. Microsoft also enlarged the scope of the original security bulletin to include Exchange 5.5 servers for the first, time, as well.

Here's where it gets interesting: On Wednesday, June 13, Microsoft released a new 3.0 version of the OWA security update. Why did it do so? Apparently, for the simple reason that the 2.0 version of the patch was itself flawed and contained "outdated files" which could ultimately crash an Exchange Server.

It is not known when Microsoft will have a version 4.0 patch available to fix its most recent update. -- Stephen Swoyer

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.


  • Microsoft Bolsters Windows IoT with NXP and SQL Server Support

    Microsoft's Internet of Things (IoT) product line is continuing to grow, with a few new developments highlighted this week.

  • Tamper Protection Now Available to Microsoft Defender ATP Subscribers

    The Microsoft Defender Advanced Threat Protection (ATP) E5 subscription plan now has an optional "tamper protection" security feature, Microsoft announced on Monday.

  • Exploring OCR, a New Way To Get Data into Excel

    Microsoft recently added a new optical character recognition feature to Excel that lets users import data from a photograph taken from a smartphone. Here's how to use it.

  • Microsoft Authenticator App To Get Real-Time Phishing Protections

    Microsoft is working on adding capabilities to its Microsoft Authenticator app to help defeat security breaches enabled by advanced attack techniques, including phishing and man-in-the-middle methods.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.