News

New Outlook Web Access Vulnerability Discovered

Microsoft Corp. Thursday night alerted administrators to a new vulnerability in Exchange 5.5’s Outlook Web Access (OWA) component that could enable an attacker to gain unauthorized access to corporate e-mail addresses.

In a security bulletin that it dispatched to members of its security mailing list, Microsoft acknowledged that an attacker could exploit the new OWA vulnerability to obtain otherwise confidential e-mail addresses.

Microsoft said that the vulnerability is actually the result of an authentication problem in an OWA function that interrogates Exchange 5.5’s global address list (GAL). Because this function doesn’t require authentication, Microsoft acknowledged, an attacker could exploit it to enumerate the e-mail addresses of users on a server.

The bulletin stressed that an attacker cannot exploit the OWA vulnerability to read, write or change a user’s e-mail, however. An OWA exploit that Microsoft patched in June affected Exchange 5.5 and Exchange 2000 systems and made it possible for an attacker to take complete control of a user’s mailbox.

According to Microsoft, the new vulnerability simply and only enables an attacker to discover the e-mail addresses of users on an Exchange 5.5 server. Exchange 2000’s OWA implementation is not affected by the vulnerability.

Microsoft released a patch to fix this problem.

Also Thursday night, the CERT Coordination Center issued an advisory concerning a buffer overflow exploit in versions 5.x and 6.x of the Gauntlet firewall from PGP Security. Gauntlet runs on several Unix platforms and is available as an e-appliance from McAfee and PGP Security. McAfee also distributes Gauntlet as part of its WebShield 4.1 product for Solaris.

According to CERT, an attacker could exploit a vulnerability in Gauntlet’s smap/smapd and CSMAP daemons to execute arbitrary code on a server with the respective privileges of the compromised daemon.

About the Author

Stephen Swoyer is a Nashville, TN-based freelance journalist who writes about technology.

Featured

  • Microsoft Offers Endpoint Configuration Manager Advice for Keeping Remote Clients Patched

    Microsoft this week offered advice for organizations using Microsoft Endpoint Configuration Manager with remote Windows systems that need to get patched, and it also announced Update 2002.

  • Azure Edge Zones Hit Preview

    Azure Edge Zones, a new edge computing technology from Microsoft designed to enable new scenarios for developers and partners, emerged as a preview release this week.

  • Microsoft Shifts 2020 Events To Be Online Only

    Microsoft is shifting its big events this year to be online only, including Ignite 2020.

  • Microsoft Browser Support for TLS 1.0 and 1.1 Ending 2H 2020

    Microsoft announced on Tuesday that its plans to drop support for Transport Layer Security (TLS) protocols 1.0 and 1.1 in its browsers will get delayed by a few months until the second half of this year.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.