CVE-1999-1368: High severity Broadcom Inoculateit vulnerability
AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the MS Exchange Server AV Option in InoculateIT until the vendor provides a fix, to avoid relying on scanning that only covers the Inbox folder tree.
InoculateIT AV Option for MS Exchange Server = disabled - Compensating control
Restrict, audit, or prohibit Exchange mailbox rules that move incoming messages out of users' primary Inbox (or into other mailboxes) so messages remain in the Inbox where InoculateIT's Exchange option performs scanning.
- Operational
Perform supplemental scanning of mailbox stores and folders outside the Inbox (for example, run manual scans or use an alternative scanning mechanism) to detect malware that may be missed by the InoculateIT Exchange option.
- Operational
Contact InoculateIT vendor/support to confirm affected versions, request a patch or remediation, and monitor vendor advisories for a fix.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1368?
CVE-1999-1368 is considered a moderate severity vulnerability due to the risk of undetected virus transmission in certain mailbox configurations.
How do I fix CVE-1999-1368?
To mitigate CVE-1999-1368, ensure that all user rules are configured to keep messages in the Inbox and regularly scan all mailboxes for viruses.
What systems are affected by CVE-1999-1368?
CVE-1999-1368 affects InoculateIT version 4.53 for Microsoft Exchange Server.
How does CVE-1999-1368 affect virus detection?
CVE-1999-1368 may allow viruses to escape detection if users' rules move infected messages out of the Inbox folder.
Is there a workaround for CVE-1999-1368?
A possible workaround for CVE-1999-1368 is to perform regular manual scans of other mailbox folders outside of the automated settings.