CVE-2010-3937
Microsoft Exchange 2007 Infinite Loop Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
Microsoft Exchange Server 2007 SP2 sobre plataformas x64 permite a usuarios autenticados remotamente provocar una denegación de servicio (bucle infinito y agotamiento MSExchangeIS) a través de una petición RPC manipulada. También conocida como "Exchange Server Infinite Loop Vulnerability".
This vulnerability allows attackers to deny services on vulnerable installations of Microsoft Exchange Server 2007. Authentication is required to exploit this vulnerability.
The specific flaw exists within store.exe during the handling of a particular MAPI call. The service will enter a loop whose termination is controlled by an attacker. If the attacker specifies an invalid value, the loop will never terminate causing the service to stop responding to requests. This results in a denial of service against the target server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-10-14 CVE Reserved
- 2010-12-14 CVE Published
- 2024-05-13 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/45297 | Third Party Advisory | |
http://www.securitytracker.com/id?1024888 | Third Party Advisory | |
http://www.us-cert.gov/cas/techalerts/TA10-348A.html | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12019 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-106 | 2020-04-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2007 Search vendor "Microsoft" for product "Exchange Server" and version "2007" | sp2, x64 |
Affected
|