Critical security issue affects all versions of Microsoft Exchange.
11 02 2009

Yesterday Microsoft released a critical security bulletin announcing that a vulnerability affecting all supported versions of Microsoft Exchange has been discovered.
The security hole allows an attacker to send a malicious email to a valid account on a non patched Exchange server, and take control of the Exchange server without any user interaction.
Microsoft has released a patch for this vulnerability and suggested that it be applied immediately.
Here is the link to the security bulletin.
I would recommend that anyone installing this patch read “known issues” under the “more information” section in Microsoft Knowledge Base Article 959239.


