CVE-2010-0816: Integer Overflow
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote e-mail servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a certain +OK response on TCP port 110, aka "Outlook Express and Windows Mail Integer Overflow Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0816?
CVE-2010-0816 has been classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2010-0816?
To fix CVE-2010-0816, users should apply the latest security updates provided by Microsoft for affected software.
Which Microsoft software is impacted by CVE-2010-0816?
CVE-2010-0816 affects Microsoft Outlook Express 5.5, 6, Windows Live Mail, and Windows Mail on various Windows operating systems.
Can CVE-2010-0816 be exploited remotely?
Yes, CVE-2010-0816 can be exploited remotely if users open a specially crafted email.
What are the risks associated with CVE-2010-0816?
Exploitation of CVE-2010-0816 can lead to arbitrary code execution, compromising the security of the affected systems.