CVE-2010-0816 describes an integer overflow in inetcomm.dll affecting Microsoft Outlook Express, Windows Live Mail, and Windows Mail across various Windows operating systems. This critical vulnerability allows remote attackers to execute arbitrary code via a crafted POP3 or IMAP response, typically during email retrieval. With a CVSS score of 9.3, it represents a high-severity threat due to its network-based attack vector, low authentication requirements, and complete compromise of confidentiality, integrity, and availability. While not listed on the CISA KEV catalog, public exploit code exists, and its EPSS score indicates a higher than average likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook_express:5.5:sp2:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook_express:6.0:sp1:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook_express:6.0:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_live_mail:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_mail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.