OSVDB ID: 25338

Title: Microsoft Exchange Collaboration Data Objects Crafted Email Code Execution

Info

Disclosure

May 09, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

May 11, 2006

Description

Microsoft Exchange contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered due to an error within the EXCDO (Exchange Collaboration Data Objects) and CDOEX (Collaboration Data Objects for Exchange) functionality when processing iCal and vCal properties in email messages. It is possible that the flaw may allow remote code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to address this vulnerability.

Products

Microsoft Corporation

Exchange Server

2003 SP1
2003 SP2
2000 Post-Service Pack 3 Update Rollup of August 2004

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/25338