To mitigate the risks that Decomposer vulnerabilities posed, the following hotfixes are available for Symantec Mail Security for Microsoft Exchange.
You must apply the appropriate hotfix to your Symantec Mail Security for Microsoft Exchange version from the following list:
SMSMSE Version |
Hotfix Number |
Hotfix contents |
Download |
---|---|---|---|
SMSMSE 7.0.0 to 7.0.4 |
SMSMSE_7.0_3966002_HF2.1 |
|
SMSMSE_7.0_3966002_HF2.1.zip |
SMSMSE 7.5.0 to 7.5.4 |
SMSMSE_7.5_3966008_VHF2.2 |
|
SMSMSE_7.5_3966008_VHF2.2.zip |
SMSMSE 6.5.8 |
SMSMSE_6.5.8_3968140_HF2.3 Note: You must upgrade to SMSMSE 6.5.8 if you have SMSMSE 6.5.7 or earlier version. |
|
SMSMSE_6.5.8_3968140_HF2.3.zip |
For the detailed instructions on how to apply the hotfix, see the Readme.txt file in the attached zip file.
For more information about the Decomposer vulnerabilities, see Advisory-I and Advisory-II.
Q: If I upgrade Symantec Mail Security for Microsoft Exchange (SMSMSE) will I need to reapply the hotfix?
A: The provided hotfix replaces components of the SMSMSE installation with components that are not impacted by the vulnerability. Upgrading or installing any product version indicated in this article would require the patch be applied.
Q: How can I determine if the patch is already applied to the currently installation of Symantec Mail Security for Microsoft Exchange?
A: To determine if the patch is already applied perform the following steps:
<Install Path>\SMSMSE\<version #>\Server
.