CVE-1999-0993
CVSS 2.0 Score 7.5 of 10 (high)
Details
Summary
CVE-1999-0993 is a vulnerability affecting Microsoft Exchange Server 5.5. This issue lies in the way Access Control Lists (ACLs) are updated. Modifications made to ACLs do not take effect immediately but are held in a cache that needs to be refreshed before the changes become active. An attacker could exploit this vulnerability by making unauthorized modifications to ACLs and waiting for the directory store cache to be refreshed before carrying out unauthorized actions. This could lead to potential security risks, such as data access by unauthorized users or system compromise. It is crucial for Microsoft Exchange Server 5.5 administrators to refresh their directory store caches regularly to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Exchange Server
Affected Vendors
- Microsoft