-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2017.0097
                      Exchange Server Security Upates
                               12 July 2017

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Microsoft Exchange Server
Operating System:     Windows
Impact/Access:        Increased Privileges           -- Remote with User Interaction
                      Cross-site Scripting           -- Remote with User Interaction
                      Provide Misleading Information -- Remote with User Interaction
Resolution:           Patch/Upgrade
CVE Names:            CVE-2017-8621 CVE-2017-8560 CVE-2017-8559
Member content until: Friday, August 11 2017

OVERVIEW

        Microsoft has released its monthly security patch update for the 
        month of July 2017. [1]
        
        This update resolves 3 vulnerabilities across the following 
        products:
        
         Microsoft Exchange Server 2010 Service Pack 3 
         Microsoft Exchange Server 2013 Cumulative Update 16 
         Microsoft Exchange Server 2013 Service Pack 1 
         Microsoft Exchange Server 2016 Cumulative Update 5


IMPACT

        Microsoft has given the following details regarding these
        vulnerabilities.
        
         Details         Impact                   Severity
        
         CVE-2017-8559   Elevation of Privilege   Important
         CVE-2017-8560   Elevation of Privilege   Important
         CVE-2017-8621   Spoofing                 Moderate


MITIGATION

        Microsoft recommends updating the software with the version made 
        available on the Microsoft Update Cataloge for the following 
        Knowledge Base articles. [1]
        
         KB4018588


REFERENCES

        [1] Security Update Guide
            https://portal.msrc.microsoft.com/en-us/security-guidance

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWWWB5Yx+lLeg9Ub1AQgmBQ/9EEawEUh5YJiShqk+ukZ57FHfRvsWdkin
L7CSnV81yveWBnixU0LmqfPnorMw7ro+E9+0+yHRPrBd0iVNbgzkZPHnw0S7dkuV
KNEB1nml7YRq4KsBzxeV5+pBmUCuSxE5cAdiKN4smTAb1ruIn6/H6PHeRS4w7D1J
FZO9tQH4KehdJjjMcnL1QA0IbwpZ/IfgQOSF/VTX7P7r6a5paGFUDu1vHHTzFM2x
fx83IVcSpbb6JZ5T9CGEIg1P/j+0XGZutjm9fpH+4lLEIQ9rzSEAf9mBJGnQ1o4h
KXQD1GUxC0guDowyBDWVbHbdZVqHK1ARhfccoqt8vUnseqACXh9JiYtV+mU3XeYy
DGkdTF7yHQUbPW/qau3s9pgD7friBkib5eLM+Q5W5hAqP65APLM6eXlsFRthupn/
4ybkvODCeOgk8LeT3a8SIYGiutjQwhgxwkmSm02VE8mBwpx/Ljd5K1vDJuOGLeJ+
mHzSHXLe4ypBLsgi4GIMQXBXkBzAO51dsxl002WnYbVZEbt6YSk57aaPknyuh3Is
lgxSN6Od3m/zjH5RnCwmb/5pxLDKlqKiL4gyaKnEtywzMaFyTF92Yc2M2Appj3tw
wQCny5X9CPd0Il1zocjgfiTa6DxNeBPuWeB1X6KYw1ZZxxWIuQKDrqCDnD1pGP7d
4y/zrU6OduU=
=jckm
-----END PGP SIGNATURE-----