Microsoft Exchange 2010 SP3 UR32
Microsoft Exchange 2010 SP3 UR32
The Microsoft Exchange 2010 SP3 UR32 reached end of service life on Oct 13, 2020 — Microsoft no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Microsoft Exchange 2010 SP3 UR32 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- msexchange
- release
- 2010
- product Label
- Microsoft Exchange
- release Label
- 2010 SP3 UR32
- codename
- lts
- latest Version
- 14.3.513.0
- release Date
- 2009-11-09
- maintained
- source Url
- https://endoflife.date/msexchange
Lifecycle Dates
- End of Service Life
- Oct 13, 2020
- Last OEM Support
- Jan 13, 2015
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Microsoft Exchange 2010 SP3 UR32 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Microsoft Exchange 2010 SP3 UR32?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Microsoft Exchange 2010 SP3 UR32 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Microsoft Exchange 2010 SP3 UR32 Support: Frequently Asked Questions
Is the Microsoft Exchange 2010 SP3 UR32 still supported?
Microsoft ended support for the Microsoft Exchange 2010 SP3 UR32 on Oct 13, 2020 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Microsoft Exchange 2010 SP3 UR32 end of service life (EOSL) date?
Microsoft lists the end of service life for the Microsoft Exchange 2010 SP3 UR32 as Oct 13, 2020.
Can I keep using the Microsoft Exchange 2010 SP3 UR32 after its EOSL date?
Yes. EOSL means Microsoft stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Microsoft Exchange 2010 SP3 UR32 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Microsoft Exchange 2010 SP3 UR32
28 published CVEs affect the Microsoft Exchange 2010 SP3 UR32, including 10 rated critical or high severity. Microsoft no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2018-8302 | CRITICAL | 9.8 | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. |
| CVE-2018-8154 | CRITICAL | 9.8 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151. |
| CVE-2020-0688 | HIGH | 8.8 | Feb 11, 2020 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'. |
| CVE-2018-16793 | HIGH | 8.6 | Sep 21, 2018 | Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page. |
| CVE-2020-17144 | HIGH | 8.4 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability |
| CVE-2019-1136 | HIGH | 8.1 | Jul 15, 2019 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. |
| CVE-2019-0724 | HIGH | 8.1 | Mar 5, 2019 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686. |
| CVE-2021-26857 | HIGH | 7.8 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2019-0686 | HIGH | 7.4 | Mar 5, 2019 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724. |
| CVE-2018-8581 | HIGH | 7.4 | Nov 14, 2018 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. |
| CVE-2013-0418 | MEDIUM | 6.8 | Jan 17, 2013 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393. NOTE: the previous information was obtained from the January 2013 CPU. Oracle has not commented on claims from an independent researcher that this is a heap-based buffer overflow in the Paradox database stream filter (vspdx.dll) |
| CVE-2019-1084 | MEDIUM | 6.5 | Jul 15, 2019 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Micros |
| CVE-2019-0588 | MEDIUM | 6.5 | Jan 8, 2019 | An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server. |
| CVE-2018-0940 | MEDIUM | 6.5 | Mar 14, 2018 | Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allows an elevation of privilege vulnerability due to how links in the body of an email message are rewritten, aka "Microsoft Exc |
| CVE-2018-0924 | MEDIUM | 6.5 | Mar 14, 2018 | Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2 |
| CVE-2010-1690 | MEDIUM | 6.4 | May 7, 2010 | The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a differe |
| CVE-2010-1689 | MEDIUM | 6.4 | May 7, 2010 | The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a differ |
| CVE-2017-8621 | MEDIUM | 6.1 | Jul 11, 2017 | Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability". |
| CVE-2019-0817 | MEDIUM | 5.4 | Apr 9, 2019 | A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0858. |
| CVE-2014-6319 | MEDIUM | 5.0 | Dec 11, 2014 | Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, aka "Outlook Web App Token Spoofing Vulnerability." |
Showing the 20 most severe of 28 known CVEs.
Get Third Party Support