Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

XADM: Send As Rights Granted to Local Administrators


View products that this article applies to.

This article was previously published under Q303709

↑ Back to the top


Symptoms

If users are members of the local Administrators group on the Exchange Server computer that their mailboxes reside on, those users may send mail representing anyone in the organization.

↑ Back to the top


Cause

When a user sends a message representing another user or group, the information store performs an access check based on the sender's current access token and the security descriptor of the object in Active Directory that the sender is attempting to represent. Microsoft Windows 2000 always considers the built-in group of local administrators to have the highest available privileges on the local computer or any computer in the domain (respectively); therefore, Windows 2000 grants any requested rights, including the Send As right.

↑ Back to the top


Resolution

To resolve this problem, obtain the latest service pack for Microsoft Exchange 2000 Server. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
301378� XGEN: How to Obtain the Latest Exchange 2000 Server Service Pack
The English version of this fix should have the following file attributes or later:

Component: Information store

Collapse this tableExpand this table
File nameVersion
Store.exe6.0.4720.22
Jcb.dll6.0.4720.22
Exoledb.dll6.0.4720.22
Excdo.dll6.0.4720.22
Mdbsz.dll6.0.4720.22

NOTE: Because of file dependencies, this update requires Microsoft Exchange Server 2000 Service Pack 1.

After this fix is applied, the information store creates a restricted user token, removing either of these built-in groups, before the information store checks for the necessary permissions.

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in Microsoft Exchange 2000 Server. This problem was first corrected in Microsoft Exchange 2000 Server Service Pack 2.

↑ Back to the top


Keywords: KB303709, kbfix, kbexchange2000sp2fix, kbexchange2000presp2fix, kbbug

↑ Back to the top

Article Info
Article ID : 303709
Revision : 4
Created on : 2/20/2007
Published on : 2/20/2007
Exists online : False
Views : 282