-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2018.0052
       Security vulnerabilities patched in Microsoft Exchange Server
                               14 March 2018

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Microsoft Exchange Server
Operating System:     Windows
Impact/Access:        Provide Misleading Information -- Remote with User Interaction
                      Access Confidential Data       -- Remote with User Interaction
                      Unauthorised Access            -- Remote with User Interaction
Resolution:           Patch/Upgrade
CVE Names:            CVE-2018-0941 CVE-2018-0940 CVE-2018-0924
Member content until: Friday, April 13 2018

OVERVIEW

        Microsoft has released its monthly security patch update for the month of
        March 2018. [1]  This update resolves 3 vulnerabilities across the following
        products:
         Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20
         Microsoft Exchange Server 2013 Cumulative Update 18
         Microsoft Exchange Server 2013 Cumulative Update 19
         Microsoft Exchange Server 2013 Service Pack 1
         Microsoft Exchange Server 2016 Cumulative Update 7
         Microsoft Exchange Server 2016 Cumulative Update 8


IMPACT

        Microsoft has given the following details regarding these vulnerabilities.
        
         Details         Impact                   Severity
         CVE-2018-0924   Information Disclosure   Low
         CVE-2018-0940   Elevation of Privilege   Important
         CVE-2018-0941   Information Disclosure   Important


MITIGATION

        Microsoft recommends updating the software with the version made available on
        the Microsoft Update Catalogue for the following Knowledge Base articles. [1]
        
         KB4073537, KB4073392


REFERENCES

        [1] Security Update Guide
            https://portal.msrc.microsoft.com/en-us/security-guidance

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWqhgfIx+lLeg9Ub1AQhJbA/+L1sHy8x4aAeDXAeqxk+L0LinCbOpUJd8
xo0S1/bErGcLZDiL3TIDB9sULXKFkJZt4SLeQwGdr2zmwp4pK55k/72CGS8AoZwh
foFN7xcXj53AYry+2Q25hNtjdNlHD+BsiVp6+Sf7xVkTqQplijevuTuxrxO3Vq94
au58AMsU4d086sAKtyy3JczS5/RuZn1JT5OFQlw97PzQzJz0D35pekkbQpYvv4Vh
slTi7AcOMFHcMdhlUyTXgJd4bxk3CrgLk0ivcrzZURdSyVj0FWP19mgYXbjGB58+
N6aWOGO8fw03bVmEojJo92rFCqLU0PDi9ZYu3ryEa7J1Z24fkFBRv1WfUbZtwrnc
deQmnyoDaopxBpZB1CVj71hh/xaQwQUq4z5aZncenu73S5oHqeYa5XysFnd0CVNu
J+9BZIzbGUd7UgzPy3DKMF/Js7Xs2j5nowp8IJvmSKJ5pYhNO0BTrfO7UIMZbvVg
d5nn1skWdAgDZmRXwrax2QI11Dz7FoNBDoB4BOxSVpH/AYtiVXGrNCl2OAwIccze
f7Snc4+9FbQiJSGBUJipExxHeS1w9NPWIjmqV5sEtq/oUHhImGA7uLciNK5jRESE
+gWxaNAklHFdQBcdu9xcBCV8fQYv+kL62XmV/y3+d7Y4iPksKbPxXlJuT/PVXMNR
gFtkjyjOS/U=
=3Og4
-----END PGP SIGNATURE-----