6.4
CVE-2010-1689
- EPSS 6.63%
- Veröffentlicht 07.05.2010 18:30:01
- Zuletzt bearbeitet 16.06.2026 23:19:08
- Erkennungen
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Version - Update sp1
Microsoft ≫ Windows 2000 Version - Update sp2
Microsoft ≫ Windows 2000 Version - Update sp3
Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Windows Xp Version - Update sp1
Microsoft ≫ Windows Xp Version - Update sp2
Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Windows Server 2003 Version - Update sp1
Microsoft ≫ Windows Server 2003 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version - Update sp1
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update -
Microsoft ≫ Exchange Server Version 2003 Update -
Microsoft ≫ Exchange Server Version 2003 Update sp1
Microsoft ≫ Exchange Server Version 2003 Update sp2
Microsoft ≫ Exchange Server Version 2007 Update -
Microsoft ≫ Exchange Server Version 2007 Update sp1
Microsoft ≫ Exchange Server Version 2007 Update sp2
Microsoft ≫ Exchange Server Version 2010 Update -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.63% | 0.93 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:P
|
http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0058.html
http://securitytracker.com/id?1023939
http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs
http://www.securityfocus.com/bid/39908