<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How the IIS vulnerability (Security Advisory 971492) affects Exchange 2003</title><link>http://msmvps.com/blogs/ehlo/archive/2009/05/22/1692927.aspx</link><description>Microsoft released recently Security Advisory 971492 , which alerts for a vulnerability in Internet Information Services (IIS) 6.0, 5.1 and 5.0 (7.0 is not affected), that can allow elevation of privilege. The vulnerability only occurs when WebDAV is</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: How the IIS vulnerability (Security Advisory 971492) affects Exchange 2003</title><link>http://msmvps.com/blogs/ehlo/archive/2009/05/22/1692927.aspx#1692995</link><pubDate>Sat, 23 May 2009 03:29:11 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1692995</guid><dc:creator>bradley</dc:creator><description>&lt;p&gt;Question: Is Outlook Web Access (OWA) vulnerable to the authentication bypass?&lt;/p&gt;
&lt;p&gt;Answer: No, OWA is not vulnerable to this vulnerability. Exchange 2007 and earlier supported the WebDAV protocol but they did so with an Exchange implementation of WebDAV which only reads/write to/from the Exchange store. It does not interact with the filesystem directly.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/srd/archive/2009/05/20/answers-to-the-iis-webdav-authentication-bypass-questions.aspx"&gt;blogs.technet.com/.../answers-to-the-iis-webdav-authentication-bypass-questions.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1692995" width="1" height="1"&gt;</description></item></channel></rss>