CVE-2010-0024 Details
Description
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-024 | CVE | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7067 | CVE | Third Party Advisory |
| http://www.us-cert.gov/cas/techalerts/TA10-103A.html | CVE | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-024 | [email protected] | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7067 | [email protected] | Third Party Advisory |
| http://www.us-cert.gov/cas/techalerts/TA10-103A.html | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft windows 2000 | All versions |
CPE
Remediation
| |
| microsoft windows xp | All versions |
CPE
Remediation
| |
| microsoft windows 2003 server | All versions |
CPE
Remediation
| |
| microsoft windows server 2003 | All versions |
CPE
Remediation
| |
| microsoft windows server 2008 | All versions |
CPE
Remediation
| |
| microsoft exchange server | 2000 sp3 2003 sp2 2007 sp1 2007 sp2 2010 - |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 9, 2020 | Modified Analysis | [email protected] |
| Feb 26, 2019 | CPE Deprecation Remap | [email protected] |
| Oct 30, 2018 | CPE Deprecation Remap | [email protected] |
| Oct 12, 2018 | CVE Modified | [email protected] |
| Sep 19, 2017 | CVE Modified | [email protected] |
| Apr 15, 2010 | Initial Analysis | [email protected] |