Microsoft's ISA Server Is Only Half Patched

Microsoft's clarification of an Internet Security and Acceleration (ISA) Server patch released this month has left at least one security expert stumped.

The heart of the matter involves security advisory (973472), which was released on Monday of last week. Bulletin 973472 describes possible vulnerabilities affecting Redmond's ISA Server, specifically an ActiveX bug associated with Office Web Components (OWC). That security advisory should not to be confused with the ISA Server fix associated with a Radius One Time password setting that was addressed in the July security patch released on Tuesday.

The important part seems to be how OWC is used in ISA Server, according to David B. Cross, a product unit manager at Microsoft's Server Products Division.

"As many customers have noticed, ISA Server 2004 and ISA Server 2006 were included [in the security advisory] on the 'Applies to' product list," Cross said in a Forefront team blog, while noting that ISA Server 2000 and Forefront Threat Management Gateway aren't included. Cross goes on to say that the OWC vulnerability affecting ISA Server can be mitigated as "ISA report generation does not use the vulnerable OWC code path."

Still confused? You're not alone.

"David's Web page seems pretty confusing. He tries to say that the servers aren't vulnerable, but at the same time, he says putting in the mitigation (killbit) doesn't break anything," stated Eric Schultze, chief technology officer at Shavlik Technologies, in an e-mail. "I read this and I'm not sure what his real recommendation is."

Schultze said Tuesday's ISA server patch pertained to a scenario involving password breaches provided the ISA Server was configured specifically for Radius One Time password parameters. That issue, after applying Tuesday's patch, is presumably resolved. However, the OWC problem is still up in the air.

"The OWC patch is simply a bad control," Schultze added. "If you're sitting on the ISA Server and you browse to an evil Web page and view an evil Excel workbook (via the OWC control), the attacker can run code on the system. The ISA Server can't be exploited unless someone at the ISA console goes to an evil Web page to view the file in question."

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.


  • How To Use .CSV Files with PowerShell, Part 1

    When it comes to bulk administration, few things are handier than .CSV files. In this two-part series, Brien demos his top techniques for working with .CSV files in PowerShell. First up: How to create a .CSV file.

  • SameSite Cookie Changes Rolled Back Until Summer

    The Chromium Project announced on Friday that it's delaying enforcement of SameSite cookie changes, and is temporarily rolling back those changes, because of the COVID-19 turmoil.

  • Basic Authentication Extended to 2H 2021 for Exchange Online Users

    Microsoft is now planning to disable Basic Authentication use with its Exchange Online service sometime in the "second half of 2021," according to a Friday announcement.

  • Microsoft Offers Endpoint Configuration Manager Advice for Keeping Remote Clients Patched

    Microsoft this week offered advice for organizations using Microsoft Endpoint Configuration Manager with remote Windows systems that need to get patched, and it also announced Update 2002.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.