← back
CVE-2010-0266

CVE-2010-0266

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 55%
from disclosure to weapon68 days
Published on NVDJul 14
1st PoC+68d
metasploitJun 1
exploitation probability
55%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.