There is a vulnerability in the image processing components of the BlackBerry Enterprise Server available for MDaemon that could allow remote code execution. More information on the vulnerability can be found on the BlackBerry KB Page
This vulnerability can be addressed by upgrading to BES 2.0.2 or newer which includes a fix OR manually applying the patch if you're running 2.0.1 or lower.
Upgrade to BES 2.0.2:
- The download for BES 2.0.2 can be found on our Alt-N downloads page
- Select your preferred language
- Select GO
- Fill out the form
- Select Continue
- Download and install BES
If you're running BES 2.0.1 or lower, to apply the update:
- Visit the BlackBerry Download page and complete the form.
- Select Next
- Agree to the Eligibility Declaration
- Select Next
- Click the Download button
- Stop MDaemon
- Extract the image.dll file into the following directories replacing the files that already exist:
- MDaemon\BES\Bin\
- MDaemon\BES\Bin\MDS\bin\
- Launch MDaemon