Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2017.0097 Exchange Server Security Upates 12 July 2017 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Microsoft Exchange Server Operating System: Windows Impact/Access: Increased Privileges -- Remote with User Interaction Cross-site Scripting -- Remote with User Interaction Provide Misleading Information -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2017-8621 CVE-2017-8560 CVE-2017-8559 Member content until: Friday, August 11 2017 OVERVIEW Microsoft has released its monthly security patch update for the month of July 2017. [1] This update resolves 3 vulnerabilities across the following products: Microsoft Exchange Server 2010 Service Pack 3 Microsoft Exchange Server 2013 Cumulative Update 16 Microsoft Exchange Server 2013 Service Pack 1 Microsoft Exchange Server 2016 Cumulative Update 5 IMPACT Microsoft has given the following details regarding these vulnerabilities. Details Impact Severity CVE-2017-8559 Elevation of Privilege Important CVE-2017-8560 Elevation of Privilege Important CVE-2017-8621 Spoofing Moderate MITIGATION Microsoft recommends updating the software with the version made available on the Microsoft Update Cataloge for the following Knowledge Base articles. [1] KB4018588 REFERENCES [1] Security Update Guide https://portal.msrc.microsoft.com/en-us/security-guidance AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBWWWB5Yx+lLeg9Ub1AQgmBQ/9EEawEUh5YJiShqk+ukZ57FHfRvsWdkin L7CSnV81yveWBnixU0LmqfPnorMw7ro+E9+0+yHRPrBd0iVNbgzkZPHnw0S7dkuV KNEB1nml7YRq4KsBzxeV5+pBmUCuSxE5cAdiKN4smTAb1ruIn6/H6PHeRS4w7D1J FZO9tQH4KehdJjjMcnL1QA0IbwpZ/IfgQOSF/VTX7P7r6a5paGFUDu1vHHTzFM2x fx83IVcSpbb6JZ5T9CGEIg1P/j+0XGZutjm9fpH+4lLEIQ9rzSEAf9mBJGnQ1o4h KXQD1GUxC0guDowyBDWVbHbdZVqHK1ARhfccoqt8vUnseqACXh9JiYtV+mU3XeYy DGkdTF7yHQUbPW/qau3s9pgD7friBkib5eLM+Q5W5hAqP65APLM6eXlsFRthupn/ 4ybkvODCeOgk8LeT3a8SIYGiutjQwhgxwkmSm02VE8mBwpx/Ljd5K1vDJuOGLeJ+ mHzSHXLe4ypBLsgi4GIMQXBXkBzAO51dsxl002WnYbVZEbt6YSk57aaPknyuh3Is lgxSN6Od3m/zjH5RnCwmb/5pxLDKlqKiL4gyaKnEtywzMaFyTF92Yc2M2Appj3tw wQCny5X9CPd0Il1zocjgfiTa6DxNeBPuWeB1X6KYw1ZZxxWIuQKDrqCDnD1pGP7d 4y/zrU6OduU= =jckm -----END PGP SIGNATURE-----