MS06-029 - KB 912442
Description: Microsoft Exchange servers running Outlook Web Access (OWA) to allow clients to remotely check emails are placing their clients at risk to a script injection vulnerability. A specially crafted email sent to the user and opened with OWA would allow the script to run. According to Microsoft "A script injection vulnerability exists that could allow an attacker to run a malicious script. If this malicious script is run, it would run in the security context of the user on the client." If you are running Microsoft Exchange OWA service, it is very important that you patch ASAP.
If you have been tracking the issue with Yahoo web mail, this should sound very familiar.
Jun 13th 2006
1 decade ago