The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS01-047: OWA Function Allows Unauthenticated User to Enumerate Global Address List
Time: 19:42 EST/00:42 GMT | News Source: ActiveWin.com | Posted By: Matthew Sabean

Among the functions Outlook Web Access (OWA) in Exchange 5.5 offers is the ability to search the global address list (GAL). By design, this is an authenticated function, implemented as a two-tier architecture - a front tier that provides a user interface and a back-end tier that actually performs the search. However, only the front tier actually checks authentication. An attacker who sent a properly formatted request to the back-end function that actually performs the search could enumerate the GAL without authenticating.

  • The vulnerability would only allow the attacker to learn users’ email aliases. It would not provide any other capabilities. Specifically, it would not give the attacker any way to create or send mail as a user; to read, change or delete mail; or to perform any other functions on the server.
  • The vulnerability is only exploitable via OWA. Exchange servers that are not configured to offer OWA are not affected by the vulnerability.
  • The vulnerability does not affect Exchange 2000, even when offering OWA.

Patch availability:
Microsoft Exchange 5.5: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=32483

Write Comment
Return to News

  Displaying 776 through 779 of 779
Prev | First
  The time now is 7:39:07 PM ET.
Any comment problems? E-mail us
#776 By 4240821 (82.115.4.100) at 1/2/2026 12:16:30 AM
https://www.pillowfort.social/posts/6526455
https://www.pillowfort.social/posts/6526341
https://www.pillowfort.social/posts/6526219
https://www.pillowfort.social/posts/6526051
https://www.pillowfort.social/posts/6525874
https://www.pillowfort.social/posts/6525694
https://www.pillowfort.social/posts/6525474
https://www.pillowfort.social/posts/6525356
https://www.pillowfort.social/posts/6525166
https://www.pillowfort.social/posts/6525101

#777 By 4240821 (82.115.4.100) at 1/4/2026 1:01:03 PM
https://www.pillowfort.social/posts/7048228
https://www.pillowfort.social/posts/7048088
https://www.pillowfort.social/posts/7048043
https://www.pillowfort.social/posts/7048005
https://www.pillowfort.social/posts/7047992
https://www.pillowfort.social/posts/7047971
https://www.pillowfort.social/posts/7047947
https://www.pillowfort.social/posts/7047845
https://www.pillowfort.social/posts/6997267
https://www.pillowfort.social/posts/6997121

#778 By 4240821 (82.115.4.100) at 1/4/2026 5:28:56 PM
https://www.pillowfort.social/posts/7052438
https://www.pillowfort.social/posts/7052362
https://www.pillowfort.social/posts/7052261
https://www.pillowfort.social/posts/7052158
https://www.pillowfort.social/posts/7052054
https://www.pillowfort.social/posts/7051958
https://www.pillowfort.social/posts/7051916
https://www.pillowfort.social/posts/7051861
https://www.pillowfort.social/posts/7051817
https://www.pillowfort.social/posts/7051704

#779 By 4240821 (82.115.4.100) at 1/4/2026 6:00:00 PM
https://www.pillowfort.social/posts/6856484
https://www.pillowfort.social/posts/6856449
https://www.pillowfort.social/posts/6856425
https://www.pillowfort.social/posts/6856394
https://www.pillowfort.social/posts/6856381
https://www.pillowfort.social/posts/6856334
https://www.pillowfort.social/posts/6856331
https://www.pillowfort.social/posts/6856325
https://www.pillowfort.social/posts/6855175
https://www.pillowfort.social/posts/6855121

Write Comment
Return to News
  Displaying 776 through 779 of 779
Prev | First
  The time now is 7:39:07 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *