CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. 漏洞列表
  3. 正文

微软Outlook Exchange远程执行代码- Shadow Brokers(englishmansdentist)零天

2017年5月9日 2119点热度 0人点赞 0条评论

漏洞类别:Mail services

漏洞等级:

漏洞信息

ENGLISHMANSDENTIST is an exploit from the recent Shadow Brokers leak. This zero day exploit is remotely exploitable using SMTP.
This information comes from the Shadow Brokers' "Equation Group" data dump.
This Zero Day is actively being exploited with the "ENGLISHMANSDENTIST" exploit.

Affected Versions:
1) MS Exchange 2000 - End of life since April 11, 2017
2) MS Exchange 2003 - End of life since April 8, 2014
3) MS Exchange 2007 - End of life since January 11, 2011

QID Detection Logic:
This QID looks for the start value of the SMTP registry key HKLM\SYSTEM\CurrentControlSet\Services\SMTPSvc and is posted if these keys are found on the following MS Exchange Versions:
1) MS Exchange 2000
2) MS Exchange 2003
3) MS Exchange 2007

漏洞危害

Successful exploitation of the vulnerability will allow remote attackers to trigger executable code on client and then send email to user.

解决方案

Customers are advised to upgrade to supported versions of Microsoft Exchange from the Microsoft Download Center.

All the affected versions of MS Exchange are End of Life and Microsoft provides no support:
1) MS Exchange 2000 - End of life since April 11, 2017
2) MS Exchange 2003 - End of life since April 8, 2014
3) MS Exchange 2007 - End of life since January 11, 2011

0day

标签: 暂无
最后更新:2017年5月9日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me