Summary
This host is missing a critical security update according to Microsoft Bulletin MS13-012.
Impact
Successful exploitation could allow an attacker to cause a denial of service condition or run arbitrary code as LocalService on the affected Exchange server.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-012
Insight
Flaws are in Microsoft Exchange Server WebReady Document Viewing and will allow remote code execution in the security context of the transcoding service on the Exchange server if a user previews a specially crafted file using Outlook Web App (OWA)
Affected
Microsoft Exchange Server 2007 Service Pack 3
Microsoft Exchange Server 2010 Service Pack 2
References
Severity
Classification
-
CVE CVE-2013-0393, CVE-2013-0418 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Microsoft .NET Framework Denial of Service Vulnerability (2990931)
- Microsoft .NET Framework Chart Control Information Disclosure Vulnerability (2567943)
- Microsoft ASP.NET Information Disclosure Vulnerability (2418042)
- Active Directory Certificate Services Web Enrollment Elevation of Privilege Vulnerability (2518295)
- Microsoft Windows Kernel Denial of Service Vulnerability (2556532)