MS10-024: Microsoft Exchange Denial of Service (uncredentialed)

medium Nessus Plugin ID 108800

Synopsis

The remote mail server may be affected by multiple vulnerabilities.

Description

The installed version of Microsoft Exchange / Windows SMTP Service is affected by at least one vulnerability :

- Incorrect parsing of DNS Mail Exchanger (MX) resource records could cause the Windows Simple Mail Transfer Protocol (SMTP) component to stop responding until the service is restarted. (CVE-2010-0024)

- Improper allocation of memory for interpreting SMTP command responses may allow an attacker to read random email message fragments stored on the affected server.
(CVE-2010-0025)

- Predictable transaction IDs are used, which could allow a man-in-the-middle attacker to spoof DNS responses.
(CVE-2010-1689)

- There is no verification that the transaction ID of a response matches the transaction ID of a query, which could allow a man-in-the-middle attacker to spoof DNS responses. (CVE-2010-1690)

Solution

Microsoft has released a set of patches for Windows 2000, XP, 2003, and 2008 as well as Exchange Server 2000, 2003, 2007, and 2010.

See Also

https://www.nessus.org/u?261981ca

Plugin Details

Severity: Medium

ID: 108800

File Name: exchange_ms10-024.nasl

Version: 1.6

Type: remote

Agent: windows

Family: Windows

Published: 4/3/2018

Updated: 8/5/2020

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows, cpe:/a:microsoft:exchange_server

Required KB Items: installed_sw/Exchange Server

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/13/2010

Vulnerability Publication Date: 4/13/2010

Exploitable With

Core Impact

Reference Information

CVE: CVE-2010-0024, CVE-2010-0025, CVE-2010-1689, CVE-2010-1690

BID: 39308, 39381, 39908, 39910

IAVB: 2010-B-0029-S

MSFT: MS10-024

MSKB: 976323, 976702, 976703, 981383, 981401, 981407