First published: Thu Dec 16 2010(Updated: )
Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2007-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3937 is classified as a medium-severity vulnerability due to its potential to cause denial of service.
To fix CVE-2010-3937, apply the latest security update for Microsoft Exchange Server 2007 SP2.
CVE-2010-3937 allows remote authenticated users to launch a denial of service attack through crafted RPC requests.
CVE-2010-3937 affects Microsoft Exchange Server 2007 SP2 running on x64 platforms.
Yes, CVE-2010-3937 can be exploited remotely by authenticated users, which leads to an infinite loop and MSExchangeIS outage.