Microsoft Exchange Outlook Web Access HTTP Response Splitting Vulnerability



Date Discovered

August 10, 2004


Microsoft Exchange Outlook Web Access (OWA) is prone to HTTP response splitting attacks. This issue could permit hostile script to be injected into client sessions, which could gain access to properties of the OWA server and Web pages hosted on the site. It is noted that the attacker must authenticate to OWA to be in a position to exploit this issue. If successfully exploited, this could allow for various attacks, such as session hijacking, and content spoofing. This issue could also be used to exploit latent vulnerabilities in Web client software.

Technologies Affected

  • Microsoft Exchange Server 5.5 SP4


Block external access at the network boundary, unless external parties require service.
Use network access controls to explicitly restrict external access by untrusted networks and hosts. Permit access for trusted networks and hosts only.

Disallow anonymous access to services. Permit access for trusted individuals only.
Only permit anonymous access to the service if it is an explicit requirement. This will reduce exposure to exploitation of this and other latent vulnerabilities.

Run all software as a nonprivileged user with minimal access rights.
As a general security precaution against Web browser attacks, users should perform non-administrative tasks as an unprivileged user with minimal access rights.

Set web browser security to disable the execution of script code or active content.
Disabling support for client-side scripting and Active Content may limit exposure to consequences of this and other latent vulnerabilities.

Communicate sensitive information over encrypted channels.
Access to Outlook Web Access should occur over SSL-protected communication channels. This may limit the consequences of this issue.

Disable any services that are not needed.
If the Outlook Web Access service is not explicitly required, it should be disabled or removed on all Exchange servers where it is present.

Microsoft has released a Security Bulletin that includes fixes to address this issue.



Discovery is credited to Amit Klein.

© 1995- Symantec Corporation

Permission to redistribute this alert electronically is granted as long as it is not edited in any way unless authorized by Symantec Security Response. Reprinting the whole or part of this alert in any medium other than electronically requires permission from


The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.

Symantec, Symantec products, Symantec Security Response, and are registered trademarks of Symantec Corp. and/or affiliated companies in the United States and other countries. All other registered and unregistered trademarks represented in this document are the sole property of their respective companies/owners.