Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-1256 | First vendor Publication | 2010-06-08 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:S/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 8.5 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 6.8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1256 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:7149 | |||
Oval ID: | oval:org.mitre.oval:def:7149 | ||
Title: | IIS Authentication Memory Corruption Vulnerability | ||
Description: | Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-1256 | Version: | 11 |
Platform(s): | Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 | Product(s): | Microsoft Internet Information Server (IIS) 6.0 Microsoft Internet Information Server (IIS) 7.0 Microsoft Internet Information Server (IIS) 7.5 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2010-06-09 | Name : Microsoft Windows Kernel Mode Drivers Privilege Escalation Vulnerabilities (9... File : nvt/secpod_ms10-032.nasl |
2010-06-09 | Name : Microsoft IIS Authentication Remote Code Execution Vulnerability (982666) File : nvt/secpod_ms10-040.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
65216 | Microsoft IIS Extended Protection for Authentication Memory Corruption A memory corruption flaw exists in Microsoft IIS. The program fails to sanitize user-supplied input when handling authentication tokens, resulting in memory corruption. With a specially crafted authentication packet, a remote authenticated attacker can execute arbitrary code. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2010-06-10 | IAVM : 2010-B-0045 - Microsoft Internet Information Services Remote Code Execution Vulnerability Severity : Category II - VMSKEY : V0024366 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-04-03 | Name : The remote web server may allow remote code execution. File : iis_7_pci.nasl - Type : ACT_GATHER_INFO |
2010-06-09 | Name : The remote web server may allow remote code execution. File : smb_nt_ms10-040.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:08:26 |
|
2024-11-28 12:21:36 |
|
2024-08-02 12:13:28 |
|
2024-08-02 01:03:39 |
|
2024-02-02 01:13:03 |
|
2024-02-01 12:03:35 |
|
2023-12-07 21:28:04 |
|
2023-09-05 12:12:09 |
|
2023-09-05 01:03:26 |
|
2023-09-02 12:12:12 |
|
2023-09-02 01:03:28 |
|
2023-08-12 12:14:29 |
|
2023-08-12 01:03:27 |
|
2023-08-11 12:12:15 |
|
2023-08-11 01:03:36 |
|
2023-08-06 12:11:47 |
|
2023-08-06 01:03:30 |
|
2023-08-04 12:11:52 |
|
2023-08-04 01:03:31 |
|
2023-07-14 12:11:49 |
|
2023-07-14 01:03:29 |
|
2023-03-29 01:13:31 |
|
2023-03-28 12:03:35 |
|
2022-10-11 12:10:32 |
|
2022-10-11 01:03:17 |
|
2021-02-06 09:22:44 |
|
2021-02-05 21:23:14 |
|
2020-05-23 00:25:34 |
|
2019-07-06 00:19:19 |
|
2019-07-04 12:02:59 |
|
2018-10-31 00:20:03 |
|
2018-10-13 00:22:56 |
|
2018-09-20 12:08:19 |
|
2017-09-19 09:23:43 |
|
2017-08-17 09:22:58 |
|
2016-09-30 01:02:22 |
|
2016-08-31 12:02:06 |
|
2016-08-05 12:02:27 |
|
2016-06-29 00:12:06 |
|
2016-04-26 19:42:51 |
|
2014-02-17 10:54:38 |
|
2013-11-11 12:38:43 |
|
2013-05-10 23:21:46 |
|