Comment Re:OWA? (Score 3, Insightful) 554
The vulnerability does not exist in OWA. The vulnerability requires that the web.config file in a subfolder enforces different permissions than those in a root folder.
You don't have to know how the computer works, just how to work the computer.