6.4

CVE-2010-1690

The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 2000 Version- Updatesp1
MicrosoftWindows 2000 Version- Updatesp2
MicrosoftWindows 2000 Version- Updatesp3
MicrosoftWindows 2000 Version- Updatesp4
MicrosoftWindows Xp Version- Updatesp1
MicrosoftWindows Xp Version- Updatesp2
MicrosoftWindows Xp Version- Updatesp3
MicrosoftWindows Server 2003 Version- Updatesp1
MicrosoftWindows Server 2003 Version- Updatesp2
MicrosoftWindows Server 2008 Version- Updatesp1
MicrosoftWindows Server 2008 Version- Updatesp2
MicrosoftWindows Server 2008 Versionr2 Update-
MicrosoftExchange Server Version2003 Update-
MicrosoftExchange Server Version2003 Updatesp1
MicrosoftExchange Server Version2003 Updatesp2
MicrosoftExchange Server Version2007 Update-
MicrosoftExchange Server Version2007 Updatesp1
MicrosoftExchange Server Version2007 Updatesp2
MicrosoftExchange Server Version2010 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 20.69% 0.954
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:N/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.