Microsoft Exchange Outlook Web Access Script Injection Vulnerability
Risk
Medium
Date Discovered
08-10-2004
Description
Microsoft Exchange Outlook Web Access (OWA) is prone to a vulnerability that may permit remote attackers to inject hostile script code into client sessions.
The vulnerability will allow hostile script to access properties of the OWA server and Web pages hosted on the site.
It is noted that the attacker must authenticate to OWA to be in a position to exploit this issue. If successfully exploited, this could allow for various attacks, such as session hijacking, and content spoofing. This issue could also be used to exploit latent vulnerabilities in Web client software.
Platforms Affected
Microsoft BackOffice 4.5
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Professional SP2
Microsoft Windows NT 4.0
Microsoft Windows NT 4.0 SP1
Microsoft Windows NT 4.0 SP2
Microsoft Windows NT 4.0 SP3
Microsoft Windows NT 4.0 SP4
Microsoft Windows NT 4.0 SP5
Microsoft Windows NT 4.0 SP6
Microsoft Windows NT 4.0 SP6a
Components Affected
Microsoft Exchange Server 5.5 SP4
Recommendations
Block external access at the network boundary, unless service is required by external parties.
Use network access controls to explicitly restrict external access by untrusted networks and hosts. Permit access for trusted networks and hosts only.
Disallow anonymous access to services. Permit access for trusted individuals only.
Only permit anonymous access to the service if it is an explicit requirement. This will reduce exposure to exploitation of this and other latent vulnerabilities.
Run all client software as a non-privileged user with minimal access rights.
As a general security precaution against Web browser attacks, users should perform non-administrative tasks as an unprivileged user with minimal access rights.
Set web browser security to disable the execution of script code or active content.
Disabling support for client-side scripting and Active Content may limit exposure to consequences of this and other latent vulnerabilities.
Run all client software as a non-privileged user with minimal access rights.
As a general security precaution against Web browser attacks, users should perform non-administrative tasks as an unprivileged user with minimal access rights.
Set web browser security to disable the execution of script code or active content.
Disabling support for client-side scripting and Active Content may limit exposure to consequences of this and other latent vulnerabilities.
Communicate sensitive information over encrypted channels.
Access to Outlook Web Access should occur over SSL-protected communication channels. This may limit the consequences of this issue.
Disable any services that are not needed.
If the Outlook Web Access service is not explicitly required, it should be disabled or removed on all Exchange servers where it is present.
Microsoft has released a Security Bulletin that includes fixes to address this issue.
Microsoft Exchange Server 5.5 SP4:
Microsoft Patch Security Update for Exchange 5.5 (KB842436)
[url=\"http://www.microsoft.com/downloads/details.aspx?FamilyId=66E4E033-5A4C-4EEC-84F1-31F0CA878092&displaylang=en\"]http://www.microsoft.com/downloads/details...&displaylang=en[/url]
References
Source: Microsoft Security Bulletin MS04-026
URL: [url=\"http://www.microsoft.com/technet/security/bulletin/ms04-026.mspx\"]http://www.microsoft.com/technet/security/...n/ms04-026.mspx[/url]
Credits
Discovery is credited to Amit Klein.
[url=\"http://securityresponse.symantec.com/avcenter/security/Content/10902.html\"]source[/url]
MS Exchange Outlook WebAccess Script Vulnerability
Moderators: Moderator, Global Moderator
Jump to
- General Category
- ↳ KillaNet Country
- ↳ 2D Graphics
- ↳ KillaNet News
- ↳ 3D & Animation
- ↳ Chatroom
- ↳ Flash
- ↳ Help & Suggestions
- ↳ Game Dev
- ↳ Audio & Video
- ↳ Introductions
- ↳ Journalism
- ↳ Phoenix Lounge
- ↳ Application Dev
- ↳ Toga Toga Toga!!!
- ↳ Photography
- ↳ Main Street Archives
- ↳ Web Design
- ↳ Fonts Icons Cursors & Screensavers
- ↳ Book Reviews
- ↳ General
- ↳ Tech Industry News
- ↳ Legal Resources
- ↳ Industry Contests
- ↳ Graphix Battle Arena
- ↳ KillaNet Contests
- ↳ Competition Archives
- ↳ Education Information
- ↳ Careers
- ↳ Game Studies
- ↳ Motivation
- ↳ Conferences & Seminars
- ↳ KillaDesign
- ↳ Animation & Film
- ↳ The Studio
- ↳ Game Development
- ↳ 2D Graphics
- ↳ Audio & Video
- ↳ 3D Graphics
- ↳ Flash
- ↳ Fonts, Icons & Emoticons
- ↳ Design Requests
- ↳ PhotoShop
- ↳ Cinema 4D
- ↳ Bryce
- ↳ Flash
- ↳ Paint Shop Pro
- ↳ Blender
- ↳ Poser
- ↳ The Darkroom
- ↳ Photo & Camera Discussion
- ↳ Photo Journalism
- ↳ Web Design Principles
- ↳ PHP & MySQL
- ↳ Designing For Print
- ↳ Writer\'s Desk
- ↳ Fiction Writing
- ↳ News Journalism
- ↳ Poetry
- ↳ Technical Writing
- ↳ Biographical Writing
- ↳ General Writing Resources
- ↳ Promotional Writing
- ↳ Film & Television
- ↳ VideoGames
- ↳ Computer Department
- ↳ General Discussion
- ↳ Windows Help
- ↳ Linux Help
- ↳ Builds & Mods
- ↳ Geek Gadgets
- ↳ Security
- ↳ Dev Discussion
- ↳ C++
- ↳ Visual Basic
- ↳ Java
- ↳ Application Skinning
- ↳ IRC Scripting
- ↳ Gaming Centre
- ↳ Guild Wars
- ↳ Aion
- ↳ Computer
- ↳ World of Warcraft
- ↳ Nintendo
- ↳ General RPG & MMORPG
- ↳ PlayStation
- ↳ XBox
- ↳ Other Consoles
- ↳ All Action
- ↳ Racers
- ↳ Sports
- ↳ FPS
- ↳ RTS
- ↳ Sim
- ↳ Casual Games
- ↳ Kids' Games
- ↳ Mobile Games
- ↳ Retro Games
- ↳ Challenges, Friendly Taunts & Discussion
- ↳ Game Requests & Bug Reports
- ↳ Open Source Games
- ↳ Puzzle Games
- ↳ HeadQuarters
- ↳ Uber Coffee Room
- ↳ KillaNet
- ↳ Coffee Room
- ↳ KillaNet
- ↳ KillaGraphix
- ↳ KillaHosting
- ↳ Marketing etc.
- ↳ Staff Issues
- ↳ Reference & Software
- ↳ Archives
- ↳ KillaBlogs
- ↳ Journalism
- ↳ Trash Can

