PT-2010-4248 · Microsoft · Exchange Server+1
Dyon Balding
·
Published
2010-09-15
·
Updated
2018-10-12
·
CVE-2010-2728
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook versions 2002 SP3, 2003 SP3, and 2007 SP2
Description
A remote code execution issue exists in Microsoft Outlook when it parses content in a specially crafted e-mail message, specifically in configurations where Outlook connects to an Exchange Server in Online Mode. This allows remote attackers to execute arbitrary code. An attacker who successfully exploits this issue could take complete control of an affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights. Configurations using Cached Exchange Mode, or those using POP or IMAP mail servers only, are not affected.
Recommendations
For Microsoft Outlook 2002 SP3, consider disabling Online Mode for Exchange Server connections until a patch is available.
For Microsoft Outlook 2003 SP3, restrict access to specially crafted e-mail messages to minimize the risk of exploitation.
For Microsoft Outlook 2007 SP2, avoid using Online Mode for Exchange Server connections in sensitive environments until the issue is resolved.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server
Outlook