SHARE
Facebook X Pinterest WhatsApp

MS Exchange 5.5 Spoofing Flaw Fixed

Written By
thumbnail
Ryan Naraine
Ryan Naraine
Aug 10, 2004

A security vulnerability in Microsoft’s Exchange
Server 5.5 Outlook Web Access could put users at risk of cross-site
scripting and spoofing attacks, the software giant warned on Tuesday.

As part of its August cycle of software updates, Microsoft released the
moderately critical MS04-026 patch
and re-released the MS04-020 bulletin
to address a new issue in Microsoft Interix.

The Exchange Server 5.5 flaw, which was reported by research firm Sanctum, resolves a software flaw
that could allow an attacker to convince a user to run a malicious script.

“An attacker who successfully exploited the vulnerability could manipulate
Web browser caches and intermediate proxy server caches, and put spoofed
content in those caches,” Microsoft said. They may also be able to exploit the vulnerability
to perform cross-site scripting attacks.”

The bug only affects Microsoft Exchange Server 5.5 SP4 and the Outlook
Web Access component.

Recommended for you...

Best Internet Security Software
Devin Partida
Mar 23, 2022
HP Wolf Security Report Shows Threat Landscape Getting Scarier
Rob Enderle
Oct 15, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
The Coming AI Threats We Aren’t Prepared For
Rob Enderle
Aug 27, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.