Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 05, 2000

More About the Exchange 2000 Server Security Vulnerability

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

The big news of the week (it wasn't a big week for Exchange Server news) is the Exchange 2000 Server security vulnerability problem. Is this vulnerability really a big deal? I'm sure Lotus is hyping it, but the matter is probably not the huge concern that some might think. Let's look at the vulnerability and the quick actions that Microsoft is taking to keep it from becoming a big problem.

First, the problem affects all versions of Exchange 2000—whether Standard or Enterprise Edition. The Exchange 2000 setup program creates the vulnerability when it adds a local machine account called EUSR_EXSTOREEVENT during setup. The account facilitates the processing of workflow and other event scripts in Exchange 5.5. During the Exchange 2000 beta, the account was left in the setup process and slipped through the cracks when the release became final. Exchange 2000 runs these scripts under the Windows system account, and as a result, this account is no longer necessary.

This vulnerability might let a malicious user log on to an Exchange 2000 server via this account. The specific damage that the user could cause depends on the type of Windows 2000 Server on which Exchange 2000 is installed. If the server is a member server, the malicious user gains only user privileges on that machine. The user could load and run code on the compromised server. If Exchange is installed on a domain controller (DC), the user might gain domain user privileges, which would let the user access other network resources and potentially cause further damage.

The severity of this concern is subject to argument. Best practices (from Microsoft and other sources) dictate that you not run Exchange 2000 on a DC. Therefore, if administrators follow those practices, the problem becomes relatively minor. However, not all organizations have the luxury of dedicating servers to specific functions such as DCs. For small businesses that run all services on one server, this matter could be more of a problem. Microsoft is acting quickly to ensure that this vulnerability won't be a major concern for anyone.

I should point out that the easiest solution is to disable or delete the account. Microsoft documents the account disabling process, and even provides a tool that deletes the account after installation. Also, Microsoft has posted a security bulletin and a support article that detail the problem and the quick and easy solutions.

Microsoft is even taking steps to ensure that the problem doesn't occur in the first place. Exchange development will release to manufacturing (RTM) a new minor version of Exchange 2000 (Rev. A) that will include the necessary fix to the setup program. The new release should be ready this week, and Microsoft will put it into the channel as soon as possible. The bulletins above also detail how to identify whether your installation is affected (most installations are) and how to correct the problem. In my humble opinion, this vulnerability isn't that big of a deal. However, Microsoft's top-notch handling of it demonstrates to me how Exchange development has made every effort to make Exchange 2000 a quality product—that's the big deal.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. Put simply, Windows 7 is not responsible for any battery life issues ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Increasing Threat of Financially Motivated Data Theft

Top 5 Key Technologies Changing The Face of Exchange and Data Protection

Deep Dive into Windows Server 2008 R2 presented by John Savill

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement