CVE-2010-1689 Details
Description
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0058.html | CVE | Broken Link |
| http://securitytracker.com/id?1023939 | CVE | Third Party AdvisoryVDB Entry |
| http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs | CVE | Third Party Advisory |
| http://www.securityfocus.com/bid/39908 | CVE | Third Party AdvisoryVDB Entry |
| http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0058.html | [email protected] | Broken Link |
| http://securitytracker.com/id?1023939 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs | [email protected] | Third Party Advisory |
| http://www.securityfocus.com/bid/39908 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-310 | Cryptographic Issues | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft windows 2000 | All versions |
CPE
Remediation
| |
| microsoft windows xp | All versions |
CPE
Remediation
| |
| microsoft windows server 2003 | All versions |
CPE
Remediation
| |
| microsoft windows server 2008 | r2 - |
CPE
Remediation
| |
| microsoft exchange server | 2003 - 2003 sp1 2003 sp2 2007 - 2007 sp1 2007 sp2 2010 - |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 9, 2020 | Reanalysis | [email protected] |
| Feb 26, 2019 | CPE Deprecation Remap | [email protected] |
| Oct 30, 2018 | CPE Deprecation Remap | [email protected] |
| May 10, 2010 | Initial Analysis | [email protected] |