
Subscribe to
Computerworld
or
Other Security Stories
December 10, 2001 (IDG News Service) -- A patch released last week to fix a flaw in the Outlook Web Access module of Microsoft Corp.'s Exchange 5.5 Server can render the Web-based e-mail system useless, administrators complained, prompting Microsoft to update and re-release its security bulletin.
"Unexpected consequences" may result due to file dependency issues if the Outlook Web Access server that the patch is applied to doesn't have Internet Explorer Version 5.0 or greater installed, Microsoft said in the revised version of bulletin MS01-057, issued late Friday.
Installing the patch on servers with an older version of Internet Explorer had various results, according to postings in a forum for Exchange administrators on Microsoft's TechNet Web site. There are reports of disabled systems that show only message headers, not the body, as well as general installation problems.
Exchange administrators could be getting used to having to deal with several versions of security bulletins and patches before their systems are patched and running again. Earlier this year, it took Microsoft three patches to plug a similar Outlook Web Access hole in Exchange 2000 (see story). Exchange 5.5 was also affected, but that patch worked on the first go.
The original bulletin, released late Thursday (see story), didn't list any caveats. The updated bulletin lists the Internet Explorer version requirement and recommends that users upgrade to Version 5.5 with Service Pack 2 or Internet Explorer 6.0. Hotfix support is available only for these latest versions of Internet Explorer, Microsoft said.
The patch is to fix a flaw in the way Outlook Web Access handles in-line script in HTML e-mail messages. An attacker can hijack a user's mailbox when his message with malicious code is opened using Internet Explorer and Outlook Web Access, according to Microsoft.
Related stories:
|
|
Print this Story |
|
Send Us Feedback |
|
E-mail this Story |
|
Digg this Story |
|
Slashdot this Story |
|
|
|
|
|
|
|
|
All Zones Application Performance Zone Business Continuity Zone Data Center Management Zone Enterprise-Class Security Zone The File Data Management Zone Grid Computing on Windows Zone Security Management Zone ITIL Best Practices Zone The SAS Zone Storage Virtualization Zone Business Intelligence and Analytics Zone |
|
|
| ||||||||
| ||||||||
| ||||||||
|


Security Management ZoneSecurity management is the process of developing a comprehensive data protection plan. It takes into account all potential threats, the existing network environment, the future needs of the organization, and lays out a multi-tiered blueprint to integrate the security technology needed to combat these threats. CDW can help keep your network and data secure. Visit the CDW Security Management Zone now See All Zones
|
Fired up about IT? Join Sharkbait and share your true tales of IT. SharkBait is the place for you to sound off about everything IT the good, the bad, and the rest of the weird stuff you deal with every day.New baits |

"Security Directions" virtual trade show2008's Code-Red Security Issues for Protecting the EnterpriseWebcasts, white papers, demos, and more. Presented in a unique 3-d environment. Enter our show right now! Click here to enter
|

In SecuritySecurity's important, and risk must be addressed, right? Sure, but watch for four signs your policies go a bit overboard. Click here to read the latest column by Jon Espenschied |
| About Us Advertise Contacts Editorial Calendar Help Desk Jobs at IDG Privacy Policy Reprints Site Map |
|
CIO The Industry Standard |