
====================================================================

                             CERT-Renater

                  Note d'Information No. 2012/VULN483
____________________________________________________________________

DATE                : 12/12/2012

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S) : Systems running Microsoft Exchange Server
                         version 2007, 2010.

======================================================================
KB2784126
http://technet.microsoft.com/en-us/security/bulletin/ms12-080
______________________________________________________________________


Microsoft Security Bulletin MS12-080 - Critical Vulnerabilities in
Microsoft Exchange Server Could Allow Remote Code Execution (2784126)

Published Date: December 11, 2012 | Updated Date: Unspecified

Version: 1.0


General Information

Executive Summary

This security update resolves publicly disclosed vulnerabilities and one
privately reported vulnerability in Microsoft Exchange Server. The most
severe vulnerabilities are in Microsoft Exchange Server WebReady
Document Viewing and could allow remote code execution in the security
context of the transcoding service on the Exchange server if a user
previews a specially crafted file using Outlook Web App (OWA). The
transcoding service in Exchange that is used for WebReady Document
Viewing is running in the LocalService account. The LocalService account
has minimum privileges on the local computer and presents
anonymous credentials on the network.

This security update is rated Critical for all supported editions of
Microsoft Exchange Server 2007 and Microsoft Exchange Server 2010.


Affected Software

Microsoft Exchange Server 2007 Service Pack 3
Microsoft Exchange Server 2010 Service Pack 1
Microsoft Exchange Server 2010 Service Pack 2


Vulnerability Information

Oracle Outside In Contains Multiple Exploitable Vulnerabilities -
CVE-2012-3214 and CVE-2012-3217

Remote code execution vulnerabilities exist in Microsoft Exchange Server
through the WebReady Document Viewing feature. These vulnerabilities
could allow remote code execution as the LocalService account if a user
views a specially crafted file through Outlook Web Access in a browser.
An attacker who successfully exploited the vulnerabilities could run
code on the affected server, but only as the LocalService account. The
LocalService account has minimum privileges on the local computer and
presents anonymous credentials on the network.


RSS Feed May Cause Exchange DoS Vulnerability - CVE-2012-4791

A denial of service vulnerability exists in Microsoft Exchange Server
when Exchange improperly handles RSS feeds. The vulnerability could
cause the Information Store service on the affected system to become
unresponsive until the process is forcibly terminated. This
unresponsive condition could cause Exchange databases to dismount, and
potentially lead to corruption of databases, affecting user mailboxes.


======================================================================

=========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
=========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44          +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
+ 75013 Paris           | email: certsvp@renater.fr     +
=========================================================
