CVE-2010-0266 is a vulnerability in Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1/SP2, where Outlook fails to properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE. This allows attackers to craft email messages with TNEF streams and MAPI attachment properties that reference local or remote files (including executables). If a user double-clicks such an attachment, Outlook may execute the referenced file without adequate warning, enabling user-assisted remote code execution. The vulnerability is triggered by the mishandling of the PR_ATTACH_METHOD property in TNEF email streams, particularly when referencing files by path, and can be exploited via intranet file shares, WebDAV, or HTTP/URL payloads.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module: ms10_045_outlook_ref_resolve.rb, which exploits a vulnerability in Microsoft Outlook (CVE-2010-0266, MS10-045). The exploit abuses the way Outlook handles certain TNEF/MAPI attachment properties, allowing an attacker to craft an email with a malicious attachment that references a file (local or remote). When the victim opens the attachment, Outlook executes the referenced file, which can be hosted on a remote WebDAV/HTTP server controlled by the attacker. The module acts as both an email sender (to deliver the malicious message) and an HTTP/WebDAV server (to serve the payload executable). The exploit is weaponized, allowing the attacker to deliver any Metasploit payload as a Windows executable. The main attack vectors are email (phishing) and network (WebDAV/HTTP). The module exposes endpoints such as an HTTP/WebDAV server (http://<attacker_host>/) and a UNC file path (\\<attacker_host>\<share>\malicious.exe) for payload delivery. The code is written in Ruby and is structured as a typical Metasploit exploit module, leveraging Metasploit's libraries for email, HTTP server, and payload generation.
This repository contains a single Metasploit module (ms10_045_outlook_ref_only.rb) that exploits a vulnerability in Microsoft Outlook (CVE-2010-0266, MS10-045). The exploit abuses the way Outlook handles certain TNEF/MAPI attachment properties, allowing an attacker to craft an email with an attachment that references a file via a UNC path (e.g., \\<attacker_host>\share\payload.exe). When the victim opens the attachment, Outlook executes the referenced file, which can be hosted remotely by the attacker. The module acts as both an HTTP/WebDAV server (to serve payloads and handle requests) and an SMTP client (to send the malicious email). The payload is a custom EXE generated by Metasploit, and the exploit is operational, requiring user interaction (opening the attachment) for successful code execution. The module is well-structured, with clear separation of email crafting, payload hosting, and request handling logic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.