CVE-2010-2568
Microsoft Windows Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
YesDecision
Descriptions
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
Shell de Windows en Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 y SP2, Server 2008 SP2 y R2, y Windows 7 permite a usuarios locales o atacantes remotos ejecutar codigo a su elección a traves de un fichero de acceso directo (1) .LNK o (2) .PIF manipulado, el cual no es manejado adecuadamente mientras se muestra el icono en el Explorador de Windows, tal y como se demostro en Julio de 2010, originalmene referenciado por malware que aprovecha CVE-2010-2772 en los sistemas Siemens WinCC SCADA.
Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-06-30 CVE Reserved
- 2010-07-18 First Exploit
- 2010-07-21 CVE Published
- 2022-09-15 Exploited in Wild
- 2022-10-06 KEV Due Date
- 2024-08-07 CVE Updated
- 2024-10-24 EPSS Updated
CWE
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://isc.sans.edu/diary.html?storyid=9181 | Broken Link | |
http://isc.sans.edu/diary.html?storyid=9190 | Broken Link | |
http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw | Media Coverage | |
http://securitytracker.com/id?1024216 | Broken Link | |
http://www.f-secure.com/weblog/archives/00001986.html | Not Applicable | |
http://www.us-cert.gov/cas/techalerts/TA10-222A.html | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11564 | Broken Link | |
https://www.geoffchappell.com/notes/security/stuxnet/ctrlfldr.htm | Third Party Advisory | |
https://securelist.com/a-fanny-equation-i-am-your-father-stuxnet/68787 |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/14403 | 2010-07-18 | |
https://www.exploit-db.com/exploits/16574 | 2010-09-21 | |
http://www.f-secure.com/weblog/archives/new_rootkit_en.pdf | 2024-08-07 | |
http://www.securityfocus.com/bid/41732 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.kb.cert.org/vuls/id/940193 | 2024-06-28 | |
http://www.microsoft.com/technet/security/advisory/2286198.mspx | 2024-06-28 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-046 | 2024-06-28 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/40647 | 2024-06-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 7 Search vendor "Microsoft" for product "Windows 7" | - | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2003 Search vendor "Microsoft" for product "Windows Server 2003" | - | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Search vendor "Microsoft" for product "Windows Server 2008" | - | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Search vendor "Microsoft" for product "Windows Server 2008" | - | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Search vendor "Microsoft" for product "Windows Server 2008" | r2 Search vendor "Microsoft" for product "Windows Server 2008" and version "r2" | itanium |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Search vendor "Microsoft" for product "Windows Server 2008" | r2 Search vendor "Microsoft" for product "Windows Server 2008" and version "r2" | x64 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Vista Search vendor "Microsoft" for product "Windows Vista" | - | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Vista Search vendor "Microsoft" for product "Windows Vista" | - | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | - | sp2, professional, x64 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | - | sp3 |
Affected
|