Microsoft Exchange and Windows SMTP Service Vulnerabilities (MS10-024)


Description   Two vulnerabilities have been identified in Microsoft Exchange and Windows SMTP Service, which could be exploited by remote attackers to cause a denial of service or gain knowledge of sensitive information.
The first issue is caused due to the Windows Simple Mail Transfer Protocol (SMTP) component incorrectly parsing malformed DNS Mail Exchanger (MX) records, which could allow unauthenticated attackers to cause a vulnerable service to stop responding until restarted, creating a denial of service condition.
The second vulnerability is caused due to the Windows Simple Mail Transfer Protocol (SMTP) component improperly allocating memory when interpreting SMTP command responses, which could allow unauthenticated attackers to read random e-mail message fragments stored on the affected server by sending invalid commands, followed by the STARTTLS command.
     
Vulnerable Products   Vulnerable Software:
Microsoft Exchange Server 2000 Service Pack 3Microsoft Exchange Server 2003 Service Pack 2Microsoft Exchange Server 2007 Service Pack 1Microsoft Exchange Server 2007 Service Pack 2Microsoft Exchange Server 2010Microsoft Windows 2000 Service Pack 4Microsoft Windows XP Service Pack 3Microsoft Windows XP Service Pack 2Microsoft Windows XP Professional x64 Edition Service Pack 2Microsoft Windows Server 2003 x64 Edition Service Pack 2Microsoft Windows Server 2003 SP2 (Itanium)Microsoft Windows Server 2003 Service Pack 2Microsoft Windows Server 2008 (32-bit) Service Pack 2Microsoft Windows Server 2008 (32-bit)Microsoft Windows Server 2008 (x64) Service Pack 2Microsoft Windows Server 2008 (x64)Microsoft Windows Server 2008 R2 (x64)
     
Solution   Apply patches : http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx
     
CVE   CVE-2010-0025
CVE-2010-0024
     
References   http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Bad DNS protocol
3.2.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2010-04-13 

 Target Type 
Server 

 Possible exploit 
Local & Remote