CVE-2010-1690

medium Microsoft
CVSS v3 Base Score
6.4
AV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS Score
20.7%
Exploitation probability in 30 days
Top 4% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
P
Availability
P
Published: May 7, 2010 (5851 days ago)
Last Modified: April 29, 2026
Vendor: Microsoft
Source: NVD

Description

The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.

CWE

CWE-20

Affected Products

microsoft windows 2000microsoft windows xpmicrosoft windows server 2003microsoft windows server 2008microsoft exchange server

References