Re: Microsoft Security Bulletin(s) for 5/9/2006



Does anyone has any problems with the installation of the patch ?

also if i understood correctly the only way for someone to exploit this
vulnerability is to send a special crafted meeting request and the user will
have to open it and accept it...is that correct ??
can it be exploited remotely without any user intervention ?

thanks


"Andy David - MVP" <adavid@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:qdq362ld7tl6773svfbh3j8gho8rc4ujt3@xxxxxxxxxx
On Wed, 10 May 2006 09:18:32 -0400, "Ted Downs"
<ted_downs@xxxxxxxxxxx> wrote:

Does this patch require/force a REBOOT of the Exchange Server?

Yes and No. Stopping all 3rd party services and Exch Services and
IISAdmin and it dependent services should prevent the requirement for
a reboot.



"Sabo, Eric" <sabo_e@xxxxxxx> wrote in message
news:A9318B8F-BD27-473A-B435-E0016B8C70D9@xxxxxxxxxxxxxxxx
I applied the patches this morning. Everything went okay no issues as
of
yet!

"Mudder69" wrote:

Watch out for 3rd party service accoutns that use the Send As security
right:

In line with Microsoft's Security Update Advisor monthly patch update
(http://www.microsoft.com/technet/security/bulletin/advance.mspx), they
have plans on releasing a patch on May 9, 2006 for Exchange 2000 Server
and Exchange Server 2003. If you are planning on installing this
update, it's important to note that this update affects user mailbox
permissions by revoking the 'Send As' permission in Exchange which has
an impact on third party products such as BlackBerry Enterprise Server
for Microsoft Exchange. Once applied, this update will prevent users on
BlackBerry Enterprise Server from sending email from a BlackBerry or
BlackBerry-enabled device.

Recommended Resolution
RIM, in conjunction with Microsoft, has provided configuration settings
that must be implemented to enable BlackBerry users to continue sending
messages. Microsoft is recommending modifying permissions in Active
Directory as outlined in the following public-facing Microsoft KBA:
http://support.microsoft.com/kb/912918

BlackBerry Technical Support Knowledge Base Article with general
information about this change can be found here:
http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/8149/8064/Support_-_User_cannot_send_messages_because_the_Send_As_permission_has_been_revoked.html?nodeid=1166052&vernum=8

Before applying this Microsoft Software Update, RIM recommends that
Administrators review these two Knowledge Base articles and take any
necessary steps appropriate for their environment. Please contact
help@xxxxxxxxxxxxxx if additional support is required for this as it
applies to BlackBerry Enterprise Server.





.



Relevant Pages

  • Re: Microsoft Security Bulletin MS02-025
    ... upgrade my entire Exchange organization to SP2 in order to apply this patch? ... > Software: Microsoft Exchange ... > seek to exploit this flaw and mount a denial of service attack. ...
    (microsoft.public.security)
  • Re: Exchange 2003 crashing
    ... I called Microsoft and got the hotfix. ... >A friend of mine recieved a patch from MS this morning. ... It appears to be a metabase patch for win2003. ... >> I have two Exchange 2003 servers in two different offices. ...
    (microsoft.public.exchange.admin)
  • Re: Microsoft Security Bulletin(s) for 5/9/2006
    ... Stopping all 3rd party services and Exch Services and ... have plans on releasing a patch on May 9, 2006 for Exchange 2000 Server ... an impact on third party products such as BlackBerry Enterprise Server ... RIM, in conjunction with Microsoft, has provided configuration settings ...
    (microsoft.public.exchange.admin)
  • Re: Microsoft Security Bulletin(s) for 5/9/2006
    ... In line with Microsoft's Security Update Advisor monthly patch update ... have plans on releasing a patch on May 9, 2006 for Exchange 2000 Server ... an impact on third party products such as BlackBerry Enterprise Server ... RIM, in conjunction with Microsoft, has provided configuration settings ...
    (microsoft.public.exchange.admin)
  • Re: Microsoft Security Bulletin(s) for 5/9/2006
    ... In line with Microsoft's Security Update Advisor monthly patch update ... have plans on releasing a patch on May 9, 2006 for Exchange 2000 Server ... an impact on third party products such as BlackBerry Enterprise Server ... RIM, in conjunction with Microsoft, has provided configuration settings ...
    (microsoft.public.exchange.admin)