CVE-1999-0993

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Dec 13, 1999
Updated: Nov 20, 2024
CWE ID 665

Summary

CVE-1999-0993 is a vulnerability affecting Microsoft Exchange Server 5.5. This issue lies in the way Access Control Lists (ACLs) are updated. Modifications made to ACLs do not take effect immediately but are held in a cache that needs to be refreshed before the changes become active. An attacker could exploit this vulnerability by making unauthorized modifications to ACLs and waiting for the directory store cache to be refreshed before carrying out unauthorized actions. This could lead to potential security risks, such as data access by unauthorized users or system compromise. It is crucial for Microsoft Exchange Server 5.5 administrators to refresh their directory store caches regularly to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Exchange Server

Affected Vendors

  • Microsoft