Blog Post

Exchange Team Blog
1 MIN READ

MS07-026: Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (931832)

The_Exchange_Team's avatar
The_Exchange_Team
Platinum Contributor
May 09, 2007

An Exchange Server related security bulletin was released yesterday. Here are some details; please go and get the patches that apply to your Exchange version!

Issued: May 08, 2007

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces two prior security updates. See the Frequently Asked Questions (FAQ) section of the bulletin for details.

Affected Software:

  • Microsoft Exchange 2000 Server Service Pack 3 with the Exchange 2000 Post-Service Pack 3 Update Rollup of August 2004
  • Microsoft Exchange Server 2003 Service Pack 1
  • Microsoft Exchange Server 2003 Service Pack 2
  • Microsoft Exchange Server 2007

Please go here for more information and links to get the updates!

Additionally, you can read about all patches released yesterday on the Microsoft Security Response Center (MSRC) blog.

EDIT: One additional note about those fixes for Exchange 2000 and 2003. Please be aware that those fixes include the "Send As" behavior change as discussed in this KB article. Functionality of your 3rd party applications might be affected. Please make sure to check the article 912918!

- Nino Bilic

Updated Jul 01, 2019
Version 2.0

53 Comments

  • Anonymous's avatar
    Anonymous
    Lei: Please don't put support issues into blog comments. Short answer: No. Open-up support a ticket, or run ExBPA/ExTRA.
  • Anonymous's avatar
    Anonymous
    This update will helpful for my issue? Recently the application log on our Exchange Server showing MSExchangeTransport error, such as," The client at "81.252.105.92" sent a "xexch50" command, and the SMTP server responded with "504 Need to authenticate first  ". And our information store was unmounted randomly with error event ID 482 of ESE, Information Store (4608) First Storage Group: An attempt to write to the file "D:Exch_logsE00tmp.log" at offset 3145728 (0x0000000000300000) for 1048576 (0x00100000) bytes failed after 0 seconds with system error 1 (0x00000001): ...
  • Anonymous's avatar
    Anonymous
    Not only is there a change in send as permissions, but store.exe now delivers mail to disabled recipients instead of NDR'ing them