The Microsoft Security Bulleting concerning this vulnerability, originally published in October of last year, has been revised to include a patch for Exchange 2000 which requires SP3 and the Post-SP3 update rollup. It seems there is still no patch for Exchange 2003 installed on Windows 2003.
Exchange 5.5 and below are not affected since the vulnerability is in the IIS code that Exchange 2000/3 use.
For more information:
http://www.microsoft.com/technet/security/Bulletin/ms04-035.mspx
Download the update for Exchange 2000 here:
http://www.microsoft.com/downloads/details.aspx?FamilyId=EDADF98A-0D26-401B-BCB7-E199477A75C2
And in case you're looking for Exchange 2000 SP3 and the Post-SP3 update:
http://www.microsoft.com/exchange/downloads/2000/sp3/default.asp
http://www.microsoft.com/downloads/details.aspx?familyid=363A57A4-8BED-4BBB-BBE4-ABC11AB04611&displaylang=en
About Amit Zinman
Currently working as Project Manager and Systems Consultant, heading and consulting on Exchange and NT/Windows 2000 based migrations and deployments for large companies such as Checkpoint, Comverse, Smarteam, Nice, Aladdin and leading Israeli Banks, Also involved in writing scripts and custom solutions for clients based on ADSI, CDO and Visual Basic and teaching Windows 2000 and Exchange 2000 in MSCE colleges and lecturing in Microsoft User Groups.
Click here for Amit Zinman's section.
Receive all the latest articles by email!
Get all articles delivered directly to your mailbox as and when they are released on MSExchange.org! Choose between receiving instant updates with the Real-Time Article Update, or a monthly summary with the Monthly Article Update. Sign up to the MSExchange.org Monthly Newsletter, written by Exchange MVP Henrik Walther, containing news, the hottest tips, Exchange links of the month and much more. Subscribe today and don't miss a thing!