CVE-2010-3888
Microsoft Windows - Task Scheduler '.XML' Local Privilege Escalation (MS10-092)
Severity Score
7.2
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.
Vulnerabilidad no especificada en Microsoft Windows para plataformas de 32 bits permite a usuarios locales obtener privilegios a través de vectores desconocidos, tal y como se pudo comprobar en Julio de 2010 cuando el gusano Stuxnet aprovecho esta vulnerabilidad y pudo ser identificada por investigadores de Kaspersky entre otros.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-10-08 CVE Reserved
- 2010-10-08 CVE Published
- 2010-11-20 First Exploit
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_ | X_refsource_misc | |
http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716 | X_refsource_misc | |
http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061 | X_refsource_misc | |
http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities | X_refsource_misc | |
http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml | X_refsource_misc | |
http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/19930 | 2012-07-19 | |
https://www.exploit-db.com/exploits/15589 | 2010-11-20 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|