Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-0027 | First vendor Publication | 2010-01-22 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0027 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:8464 | |||
Oval ID: | oval:org.mitre.oval:def:8464 | ||
Title: | URL Validation Vulnerability | ||
Description: | The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-0027 | Version: | 12 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 7 | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2012-03-22 | MS10-002 Internet Explorer Object Memory Use-After-Free |
2010-07-12 | Internet Explorer "Aurora" Memory Corruption |
OpenVAS Exploits
Date | Description |
---|---|
2010-02-10 | Name : Microsoft Windows Shell Handler Could Allow Remote Code Execution Vulnerabili... File : nvt/secpod_ms10-007.nasl |
2010-01-22 | Name : Microsoft Internet Explorer Multiple Vulnerabilities (978207) File : nvt/secpod_ms10-002.nasl |
2010-01-20 | Name : Microsoft Internet Explorer Remote Code Execution Vulnerability (979352) File : nvt/gb_ms_ie_dep_remote_code_exec_vuln.nasl |
2009-11-30 | Name : Microsoft Internet Explorer 'XSS Filter' XSS Vulnerabilities - Nov09 File : nvt/secpod_ms_ie_xss_filter_xss_vuln_nov09.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
62245 | Microsoft Windows Shell Handler ShellExecute API Crafted URL Arbitrary Comman... |
61909 | Microsoft IE Unspecified Crafted URL Handling Arbitrary Code Execution |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2010-02-18 | IAVM : 2010-A-0029 - Microsoft Windows Shell Handler Remote Code Execution Vulnerability Severity : Category II - VMSKEY : V0022683 |
Snort® IPS/IDS
Date | Description |
---|---|
2017-10-03 | Microsoft Windows Shell Handler remote code execution attempt RuleID : 44218 - Revision : 1 - Type : OS-WINDOWS |
2017-10-03 | Microsoft Windows Shell Handler remote code execution attempt RuleID : 44217 - Revision : 1 - Type : OS-WINDOWS |
2017-10-03 | Microsoft Windows Shell Handler remote code execution attempt RuleID : 44216 - Revision : 1 - Type : OS-WINDOWS |
2017-09-06 | Microsoft Internet Explorer CTableLayout memory corruption attempt RuleID : 43831 - Revision : 3 - Type : BROWSER-IE |
2017-09-06 | Microsoft Internet Explorer CTableLayout memory corruption attempt RuleID : 43830 - Revision : 3 - Type : BROWSER-IE |
2016-04-05 | Microsoft Internet Explorer invalid object access memory corruption attempt RuleID : 37947 - Revision : 1 - Type : BROWSER-IE |
2016-04-05 | Microsoft Internet Explorer invalid object access memory corruption attempt RuleID : 37946 - Revision : 1 - Type : BROWSER-IE |
2016-04-05 | Microsoft Internet Explorer deleted object access memory corruption attempt RuleID : 37945 - Revision : 1 - Type : BROWSER-IE |
2016-04-05 | Microsoft Internet Explorer invalid object access memory corruption attempt RuleID : 37944 - Revision : 1 - Type : BROWSER-IE |
2016-04-05 | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt RuleID : 37881 - Revision : 2 - Type : BROWSER-IE |
2015-03-27 | Microsoft Internet Explorer CTableLayout memory corruption attempt RuleID : 33570 - Revision : 3 - Type : BROWSER-IE |
2015-03-27 | Microsoft Internet Explorer CTableLayout memory corruption attempt RuleID : 33569 - Revision : 3 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer CTableLayout memory corruption attempt RuleID : 28353 - Revision : 7 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer CTableLayout memory corruption attempt RuleID : 28352 - Revision : 7 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt RuleID : 24872 - Revision : 8 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt RuleID : 24871 - Revision : 8 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt RuleID : 24870 - Revision : 6 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt RuleID : 24869 - Revision : 6 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer invalid object access memory corruption attempt RuleID : 19937 - Revision : 12 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer CTableLayout memory corruption attempt RuleID : 18951 - Revision : 12 - Type : BROWSER-IE |
2014-01-10 | Microsoft Windows Shell Handler remote code execution attempt RuleID : 16414 - Revision : 14 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt RuleID : 16377 - Revision : 18 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer CTableLayout memory corruption attempt RuleID : 16376 - Revision : 13 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer deleted object access memory corruption attempt RuleID : 16369 - Revision : 14 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer invalid object access memory corruption attempt RuleID : 16367 - Revision : 17 - Type : BROWSER-IE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-02-09 | Name : An API function on the remote host has a code execution vulnerability. File : smb_nt_ms10-007.nasl - Type : ACT_GATHER_INFO |
2009-01-21 | Name : Arbitrary code can be executed on the remote host through a web browser. File : smb_nt_ms10-002.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:09:29 |
|
2024-11-28 12:20:50 |
|
2023-12-07 21:28:05 |
|
2021-07-27 00:24:33 |
|
2021-07-24 01:44:10 |
|
2021-07-24 01:06:47 |
|
2021-07-23 21:25:00 |
|
2020-05-23 00:25:02 |
|
2019-02-26 17:19:32 |
|
2018-10-31 00:20:00 |
|
2018-10-13 00:22:53 |
|
2018-10-11 00:19:45 |
|
2017-09-19 09:23:34 |
|
2017-08-17 09:22:52 |
|
2016-08-31 12:02:01 |
|
2016-08-05 12:02:22 |
|
2016-06-28 17:59:24 |
|
2016-04-26 19:29:16 |
|
2014-02-17 10:53:04 |
|
2014-01-19 21:26:28 |
|
2013-11-11 12:38:31 |
|
2013-05-10 23:13:38 |
|