6.4

CVE-2010-1690

The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Version - Update sp1
Microsoft ≫ Windows 2000 Version - Update sp2
Microsoft ≫ Windows 2000 Version - Update sp3
Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Windows Xp Version - Update sp1
Microsoft ≫ Windows Xp Version - Update sp2
Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Windows Server 2003 Version - Update sp1
Microsoft ≫ Windows Server 2003 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version - Update sp1
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update -
Microsoft ≫ Exchange Server Version 2003 Update -
Microsoft ≫ Exchange Server Version 2003 Update sp1
Microsoft ≫ Exchange Server Version 2003 Update sp2
Microsoft ≫ Exchange Server Version 2007 Update -
Microsoft ≫ Exchange Server Version 2007 Update sp1
Microsoft ≫ Exchange Server Version 2007 Update sp2
Microsoft ≫ Exchange Server Version 2010 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.57% 0.93
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:N/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0058.html
Broken Link
http://securitytracker.com/id?1023939
Third Party Advisory
VDB Entry
http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs
Third Party Advisory
http://www.securityfocus.com/bid/39910
Patch
Third Party Advisory
VDB Entry