---
title: "Microsoft varnar för säkerhetshål i Exchange 5.5"
type: "forum-thread"
url: "https://www.webforum.nu/amne/datasakerhet/28758-microsoft-varnar-för-säkerhetshål-i-exchange-5-5"
topic: "Datasäkerhet"
topic_url: "https://www.webforum.nu/amne/datasakerhet"
author: "inge"
published: "2001-12-10T14:19:00.000Z"
updated: "2001-12-10T17:19:00.000Z"
replies: 2
views: 305
page: 1
pages: 1
language: "sv-SE"
site: "webForum — webforum.nu"
rights: "Upphovsrätten till varje inlägg tillhör dess författare."
attribution: "Citera som: webForum, https://www.webforum.nu/amne/datasakerhet/28758-microsoft-varnar-för-säkerhetshål-i-exchange-5-5"
---

# Microsoft varnar för säkerhetshål i Exchange 5.5

## #1 — inge, 2001-12-10T14:19Z

Microsoft varnar för säkerhetshål i Exchange 5.5
10:13 - Computer Sweden: Företag som gjort det möjligt för sina anställda att komma åt sina e-postkonton via Microsoft Exchange 5.5:s webbgränssnitt riskerar att exponera kontona för skriptattacker via e-post. (Teknik)  <http://www.idg.se/idgse/default.asp>

Permalänk: https://www.webforum.nu/p/28758

## #2 — stoffe-2k, 2001-12-10T16:23Z

MS skickade ut varning och patch dagarna innan IDG.se gick ut med det...

Permalänk: https://www.webforum.nu/p/404541

## #3 — stoffe-2k, 2001-12-10T17:19Z

fr 2001-12-07 00:35

> \-----BEGIN PGP SIGNED MESSAGE-----
>
> \- ----------------------------------------------------------------------
> Title:      Specially Formed Script in HMTL Mail can Execute in
>             Exchange 5.5 OWA
> Date:       06 December 2001
> Software:   Microsoft Exchange 5.5 Server Outlook Web Access
> Impact:     Run Code of Attacker's Choice
> Max Risk:   Medium
> Bulletin:   MS01-057
>
> Microsoft encourages customers to review the Security Bulletin at:  <http://www.microsoft.com/technet/security/bulletin/MS01-057.asp.> 
> \- ----------------------------------------------------------------------
>
> Patch Availability:
> \===================
>  \- A patch is available to fix this vulnerability. Please read the 
>    Security Bulletin at
>    <http://www.microsoft.com/technet/security/bulletin/ms01-057.asp> 
>    for information on obtaining this patch.

lö 2001-12-08 04:15

> \-----BEGIN PGP SIGNED MESSAGE-----
>
> \- ----------------------------------------------------------------------
> Title:      Specially Formed Script in HTML Mail can Execute in
>             Exchange 5.5 OWA
> Date:       06 December 2001
> Revised:    07 December 2001 (version 2.0)
> Software:   Microsoft Exchange 5.5 Server Outlook Web Access
> Impact:     Run Code of Attacker's Choice
> Max Risk:   Medium
> Bulletin:   MS01-057
>
> Microsoft encourages customers to review the Security Bulletin at:  <http://www.microsoft.com/technet/security/bulletin/MS01-057.asp.> 
> \- -
> \- ----------------------------------------------------------------------
>
> Reason for Revision:
> \====================
> On December 6, 2001 Microsoft released the original version of this bulletin. On December 7, 2001 an issue relating to file dependencies for the patch was identified and the bulletin was updated and re-released to include this information. Specifically, for this patch to function properly, the Outlook Web Access (OWA) server on which the patch is installed must have Internet Explorer (IE) 5.0 or greater installed. If the patch is installed on a system with a version of IE older than 5.0, unexpected consequences may result. The "Caveats" section has been updated to include version requirements for this patch. In addition, it contains version recommendations for dependent components that are applicable at the time of this writing. In addition, the FAQ contains remediation information for customers who have applied this patch on systems with versions of IE older than 5.0.

Permalänk: https://www.webforum.nu/p/404542

---

Tråden på webben: https://www.webforum.nu/amne/datasakerhet/28758-microsoft-varnar-för-säkerhetshål-i-exchange-5-5
