Comment Re:OWA? (Score 3, Insightful) 554
The vulnerability does not exist in OWA. The vulnerability requires that the web.config file in a subfolder enforces different permissions than those in a root folder.
Some people manage by the book, even though they don't know who wrote the book or even what book.