Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-0478 | First vendor Publication | 2010-04-14 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0478 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:7001 | |||
Oval ID: | oval:org.mitre.oval:def:7001 | ||
Title: | Media Services Stack-based Buffer Overflow Vulnerability | ||
Description: | Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-0478 | Version: | 5 |
Platform(s): | Microsoft Windows 2000 | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 |
SAINT Exploits
Description | Link |
---|---|
Windows Media Unicast Service transport information packet buffer overflow | More info here |
ExploitDB Exploits
id | Description |
---|---|
2010-04-28 | Windows Media Services ConnectFunnel Stack Buffer Overflow |
OpenVAS Exploits
Date | Description |
---|---|
2010-04-14 | Name : Microsoft Windows Media Services Remote Code Execution Vulnerability (980858) File : nvt/secpod_ms10-025.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
63726 | Microsoft Windows Media Unicast Service Transport Packet Handling Remote Over... Windows is prone to an overflow condition. The Windows Media Unicast Service fails to properly sanitize user-supplied input resulting in a stack overflow. With a specially crafted FunnelConnect request, a remote attacker can potentially cause arbitrary code execution. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2010-04-29 | IAVM : 2010-A-0068 - Microsoft Windows Media Services Remote Code Execution Vulnerability Severity : Category II - VMSKEY : V0024076 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows Media Service stack overflow attempt RuleID : 16541 - Revision : 14 - Type : OS-WINDOWS |
Metasploit Database
id | Description |
---|---|
2010-04-13 | Windows Media Services ConnectFunnel Stack Buffer Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-04-27 | Name : The remote media service is affected by a remote code execution vulnerability. File : smb_kb_980858.nasl - Type : ACT_GATHER_INFO |
2010-04-13 | Name : The remote media service has a buffer overflow vulnerability. File : smb_nt_ms10-025.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:08:47 |
|
2024-11-28 12:21:08 |
|
2021-05-04 12:11:06 |
|
2021-04-22 01:11:40 |
|
2020-05-23 13:16:54 |
|
2020-05-23 00:25:15 |
|
2019-04-30 21:19:21 |
|
2018-10-13 00:22:54 |
|
2017-09-19 09:23:38 |
|
2016-04-26 19:34:08 |
|
2014-02-17 10:53:45 |
|
2014-01-19 21:26:37 |
|
2013-11-11 12:38:38 |
|
2013-05-10 23:17:42 |
|