About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 
 

NEWS

 
 
Microsoft investigates possible Exchange 2003 flaw
Outlook Web Access component may enable security breach
 

 
By Joris Evers, IDG News Service November 21, 2003 

Microsoft is investigating a potential security issue with Exchange Server 2003, which would be the first since the e-mail server was launched last month.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH

The potential flaw lies in the Outlook Web Access (OWA) component of Exchange Server 2003. A network administrator at a Nashville, Tennessee, provider of investment performance reporting tools found that users logging in to OWA could be logged in to another user's mailbox at random and have full access privileges.

"This seems to be a major security flaw and we have had to shut off OWA indefinitely because of the issue," the network administrator wrote in a posting to NTBugtraq, a well-known security mailing list.

A preliminary investigation by Microsoft indicated that the issue occurs only with Kerberos authentication disabled, which the vendor said is uncommon. "We recommend that our customers ensure that Kerberos authentication is enabled, which is the default configuration," Microsoft said in a statement Friday.

Microsoft has already developed a patch, which is currently being tested, the network administrator said in an e-mail message. Microsoft would not comment on any patch because it is still investigating the issue.

"Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, including providing a fix and additional mitigation information if either is warranted," the vendor said.


MORE SECURITY WHITE PAPERS
»  AT&T - AHA Endorses AT&T's Voice and Data Service for Hospitals.
To work more efficiently with other hospitals and serve patients better, hospitals must keep up with technology and find ways to create secure databases. AT&T has the capabilities to help.

»  AT&T - Improving the View with IP Videoconferencing
Videoconferencing has become an effective face-to-face equivalent for many organizations. Whether you are new to videoconferencing or have been using ISDN technology for years, IP videoconferencing is relatively easy to deploy.

»  AT&T - Tell Us Where It Hurts.
In order to keep up with the rising expectation of patients and staff, healthcare providers need to upgrade their communications with reliable network and services. AT&T has the expertise to help.

»  AT&T - A Patient Data Network for the Future

»  Fortify Software - JavaScript Hijacking

»  Riverbed - Riverbed RiOS 4.0: Raising the Bar in Wide-Area Data Services



SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.



 
 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no