1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

MS13-012 - Critical : Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code...

Discussion in 'Security Updates' started by Microsoft Security, Feb 12, 2013.

  1. Severity Rating: Critical
    Revision Note: V1.0 (February 12, 2013): Bulletin published.
    Summary: This security update resolves publicly disclosed vulnerabilities in Microsoft Exchange Server. The most severe vulnerability is in Microsoft Exchange Server WebReady Document Viewing, and could allow remote code execution in the security context of the transcoding service on the Exchange server if a user previews a specially crafted file using Outlook Web App (OWA). The transcoding service in Exchange that is used for WebReady Document Viewing is running in the LocalService account. The LocalService account has minimum privileges on the local computer and presents anonymous credentials on the network.

    View the full article
     

Share This Page