PT-2010-1849 · Microsoft · Windows Server 2003+5

Publicado

2010-04-14

·

Atualizado

2020-04-09

·

CVE-2010-0024

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 version SP4 Microsoft Windows XP versions SP2 through SP3 Microsoft Windows Server 2003 version SP2 Microsoft Windows Server 2008 versions Gold through SP2 and R2 Microsoft Exchange Server 2003 version SP2
Description A denial of service issue exists due to improper parsing of MX records by the SMTP component, allowing remote DNS servers to cause a service outage via a crafted response to a DNS MX record query. The vulnerability can be exploited without authentication by sending a specially crafted network message to a computer running the SMTP service, causing the SMTP service to stop responding until restarted.
Recommendations For Microsoft Windows 2000 SP4, update the SMTP component to prevent the vulnerability. For Microsoft Windows XP SP2 and SP3, update the SMTP component to prevent the vulnerability. For Microsoft Windows Server 2003 SP2, update the SMTP component to prevent the vulnerability. For Microsoft Windows Server 2008 Gold, SP2, and R2, update the SMTP component to prevent the vulnerability. For Microsoft Exchange Server 2003 SP2, update the SMTP component to prevent the vulnerability. As a temporary workaround, consider restarting the SMTP service after a denial of service incident to restore functionality.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0024

Produtos afetados

Exchange Server
Exchange Server 2003
Windows 2000
Windows Server 2003
Windows Server 2008
Windows Xp