CVE-2010-2728: Buffer Overflow
Published Sep 15, 2010
·Updated
Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
Affected Software
3 affected components
Microsoft Outlook=2003-sp3
Microsoft Outlook=2002-sp3
Microsoft Outlook=2007-sp2
Event History
Sep 15, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2728?
CVE-2010-2728 has a critical severity rating, allowing remote attackers to execute arbitrary code.
2
How do I fix CVE-2010-2728?
To fix CVE-2010-2728, apply the security updates provided by Microsoft for affected versions of Outlook.
3
Which versions of Microsoft Outlook are affected by CVE-2010-2728?
CVE-2010-2728 affects Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2.
4
How does CVE-2010-2728 exploit occur?
CVE-2010-2728 exploits a heap-based buffer overflow via a crafted email message.
5
Can CVE-2010-2728 lead to data loss?
Yes, CVE-2010-2728 can lead to data loss or unauthorized access due to remote code execution.