NEWS

Microsoft warns of another hole in Outlook Web Access
By Joris Evers
December 7, 2001 6:41 am PT
A FLAW IN the Outlook Web Access module in Microsoft's Exchange 5.5 e-mail system could allow unauthorized access to user's mailboxes, the company warned late Thursday.
The problem lies in the way Outlook Web Access handles inline script in HTML e-mail messages, Microsoft said in a security bulletin. An attacker can get full control over a mailbox when his e-mail with embedded malicious code is opened using Microsoft's Internet Explorer browser and Outlook Web Access, Microsoft said.
Although the attacker can delete mailbox contents, move messages, and send messages as if they were the user, it isn't possible to send e-mail to addresses in the user's address book, preventing a mass-mailing attack, Microsoft said.
Outlook Web Access allows users to access their e-mail via the Web, rather than using the Outlook client software on their PC.
Microsoft is having a tough time securing Outlook Web Access. In June it took the company three patches to plug a similar hole. The first and second patches for the hole, which affected both Exchange 2000 Server and Exchange 5.5, left administrators with dysfunctional e-mail systems.
Microsoft, which gives the vulnerability a "moderate" severity rating, urges administrators who have deployed Outlook Web Access to immediately install a patch to fix the flaw. The patch is available from Microsoft's TechNet Web site.
Microsoft's security bulletin can be viewed on the Web at: www.microsoft.com/technet/security/bulletin/MS01-057.asp
Joris Evers is an Amsterdam correspondent for the IDG News Service, an InfoWorld affiliate.
 RELATED SUBJECTS

Security
Business News
Web Technologies
SPONSORED WHITE PAPERS
EMC
- Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust
- Are you ready for Sobig.G? Learn how to protect your email systems.
CDW
- Personal attention. CDW. The Right Technology. Right Away.
EMC
- Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel
- Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco
- FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc.
- "Mass Consolidation Hits the Web-Search Market"
McDATA
- Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies
- Overcoming Common Firewall Limitations
Lucent Technologies
- Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia
- Get the scoop! Mobilizing business white papers & case studies.
BMC Software
- Maximize the Potential of Enterprise Data: Free white paper!
Network Associates
- Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust
- Manage identities across applications. Improve productivity.
Stalker Software
- CommuniGate Pro - Transform your Email and Calendaring
Remedy
- A NEW Gartner Research Note:Producing Quality IT Services
Search the IDG White Paper Library:
|
SPONSORED LINKS
|