CVE-2012-4791: Code Injection
Published Dec 12, 2012
·Updated
Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
Affected Software
3 affected components
Microsoft Exchange Server=2007-sp3
Microsoft Exchange Server=2010-sp1
Microsoft Exchange Server=2010-sp2
Event History
Dec 12, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4791?
CVE-2012-4791 is classified as a denial of service (DoS) vulnerability affecting Microsoft Exchange Server.
2
How do I fix CVE-2012-4791?
To fix CVE-2012-4791, apply the security update provided by Microsoft in the relevant security bulletin.
3
What versions of Microsoft Exchange are affected by CVE-2012-4791?
CVE-2012-4791 affects Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2.
4
What type of attack does CVE-2012-4791 enable?
CVE-2012-4791 enables remote authenticated users to cause a denial of service by subscribing to a malicious RSS feed.
5
Can CVE-2012-4791 be exploited without authentication?
No, CVE-2012-4791 requires remote authenticated access to exploit the vulnerability.