CVE-2009-0098: Critical severity Microsoft Exchange Server vulnerability
Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What are the consequences of exploiting CVE-2009-0098?
Exploiting CVE-2009-0098 allows remote attackers to execute arbitrary code on affected Exchange Server instances.
What versions are affected by CVE-2009-0098?
CVE-2009-0098 affects Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1.
How can I mitigate the risk associated with CVE-2009-0098?
To mitigate CVE-2009-0098, users should apply the latest security patches provided by Microsoft for the affected Exchange Server versions.
Is CVE-2009-0098 a critical vulnerability?
CVE-2009-0098 is considered a serious vulnerability due to its potential for remote code execution.
What kind of messages can trigger CVE-2009-0098?
CVE-2009-0098 can be triggered by a crafted Transport Neutral Encapsulation (TNEF) message.