MS10-024: Microsoft Exchange Denial of Service (uncredentialed)

Medium Nessus Plugin ID 108800

Synopsis

The remote mail server may be affected by multiple vulnerabilities.

Description

The installed version of Microsoft Exchange / Windows SMTP Service is affected by at least one vulnerability :

- Incorrect parsing of DNS Mail Exchanger (MX) resource records could cause the Windows Simple Mail Transfer Protocol (SMTP) component to stop responding until the service is restarted. (CVE-2010-0024)

- Improper allocation of memory for interpreting SMTP command responses may allow an attacker to read random email message fragments stored on the affected server.
(CVE-2010-0025)

- Predictable transaction IDs are used, which could allow a man-in-the-middle attacker to spoof DNS responses.
(CVE-2010-1689)

- There is no verification that the transaction ID of a response matches the transaction ID of a query, which could allow a man-in-the-middle attacker to spoof DNS responses. (CVE-2010-1690)

Solution

Microsoft has released a set of patches for Windows 2000, XP, 2003, and 2008 as well as Exchange Server 2000, 2003, 2007, and 2010.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2010/ms10-024

Plugin Details

Severity: Medium

ID: 108800

File Name: exchange_ms10-024.nasl

Version: 1.5

Type: remote

Agent: windows

Family: Windows

Published: 2018/04/03

Updated: 2018/11/15

Dependencies: 108804

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.4

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

CVSS v3.0

Base Score: 6.5

Temporal Score: 6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows, cpe:/a:microsoft:exchange_server

Required KB Items: installed_sw/Exchange Server

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2010/04/13

Vulnerability Publication Date: 2010/04/13

Exploitable With

Core Impact

Reference Information

CVE: CVE-2010-0024, CVE-2010-0025, CVE-2010-1689, CVE-2010-1690

BID: 39308, 39381, 39908, 39910

MSFT: MS10-024

IAVB: 2010-B-0029

MSKB: 976323, 976702, 976703, 981383, 981401, 981407