This security update resolves two privately reported vulnerabilities in Outlook Web Access (OWA) for Microsoft Exchange Server. An attacker who successfully exploited these vulnerabilities could gain access to an individual OWA client s session data, allowing elevation of privilege. The attacker could then perform any action the user could perform from within the individual client s OWA session.

http://www.securiteam.com/windowsntf...FP072KOUE.html