← Back

CVE-2010-0266

nvd nist
Published: Jul 15, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."

Affected (4)

Products: Microsoft: Outlook
1 product
Outlook
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2002 sp3
Running on/withPlatform Versions
Microsoft
Office
Version xp sp3
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2003 sp3
Running on/withPlatform Versions
Microsoft
Office
Version 2003 sp3
Configuration C
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Microsoft
Version 2007 sp1
Version 2007 sp2
Running on/withPlatform Versions
Microsoft
Office
Version 2007 sp1
Microsoft
Office
Version 2007 sp2

Timeline

No history available yet.