Vulnerability record · CVE-2010-0266 · published 15 July 2010
CVE-2010-0266: Microsoft Outlook SMB attachment code execution flaw
Microsoft · Outlook
Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP1/SP2 fail to properly verify e-mail attachments whose PR_ATTACH_METHOD property is set to ATTACH_BY_REFERENCE. A crafted message can therefore cause Outlook to treat a remote reference as a local attachment, leading to arbitrary code execution. The flaw matters because it turns a simple received e-mail into a code-execution path on the client.
Description
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution in a widely deployed mail client with a high EPSS score, though exploitation requires user interaction and no KEV listing exists.
What it is
Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP1/SP2 fail to properly verify e-mail attachments whose PR_ATTACH_METHOD property is set to ATTACH_BY_REFERENCE. A crafted message can therefore cause Outlook to treat a remote reference as a local attachment, leading to arbitrary code execution. The flaw matters because it turns a simple received e-mail into a code-execution path on the client.
Impact
An attacker who convinces a user to open or interact with the crafted message can execute arbitrary code in the context of the logged-on user. That gives full compromise of the user's data and credentials on the affected workstation.
Attack surface
Reached remotely via a crafted e-mail message delivered to the victim; the CVSS vector AV:N/AC:M/Au:N indicates network delivery with no authentication, but user interaction is required to trigger the attachment handling.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high (0.553, 98.98th percentile), indicating substantial predicted exploitation activity. References are vendor and government advisories only, with no public exploit tag supplied.
What to do
- Apply Microsoft security bulletin MS10-045 for the affected Outlook versions.
- Upgrade or retire Outlook 2002, 2003, and 2007 installations that cannot be patched.
- Block or restrict outbound SMB (TCP 445) from client networks to prevent referenced attachments from reaching attacker-controlled shares.
- Warn users not to open unexpected attachments or messages from untrusted senders.
- Enforce attachment filtering at the mail gateway for suspicious reference-style attachments.
Detection
- Monitor Outlook client processes for unexpected outbound SMB connections to external hosts.
- Alert on e-mail messages containing ATTACH_BY_REFERENCE attachment properties, especially with remote UNC paths.
- Review endpoint logs for child processes spawned by outlook.exe.
- Correlate mail gateway logs with endpoint network telemetry for SMB access following message delivery.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0266 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0266), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.