Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-2564 | First vendor Publication | 2010-08-11 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2564 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12011 | |||
Oval ID: | oval:org.mitre.oval:def:12011 | ||
Title: | Movie Maker Memory Corruption Vulnerability | ||
Description: | Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-2564 | Version: | 12 |
Platform(s): | Microsoft Windows XP Microsoft Windows Vista | Product(s): | Movie Maker 2.1 Movie Maker 2.6 Movie Maker 6.0 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 3 |
SAINT Exploits
Description | Link |
---|---|
Microsoft Windows Movie Maker MediaClipString Buffer Overflow | More info here |
OpenVAS Exploits
Date | Description |
---|---|
2010-08-11 | Name : Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability... File : nvt/secpod_ms10-050.nasl |
2010-08-11 | Name : Remote Code Execution Vulnerability in Cinepak Codec (982665) File : nvt/secpod_ms10-055.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
66986 | Microsoft Windows Movie Maker Imported Projector File (.MSWMM) String Parsing... Windows Movie Maker contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the way that Windows Movie Maker handles specially crafted project files. This may allow an attacker to take complete control of an affected system. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows Movie Maker string size overflow attempt RuleID : 19063 - Revision : 16 - Type : FILE-MULTIMEDIA |
2014-01-10 | Microsoft Windows Movie Maker string size overflow attempt RuleID : 17135 - Revision : 16 - Type : FILE-MULTIMEDIA |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-08-11 | Name : Arbitrary code can be executed on the remote host through Windows Movie Maker. File : smb_nt_ms10-050.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:07:51 |
|
2024-11-28 12:22:20 |
|
2021-05-04 12:11:46 |
|
2021-04-22 01:12:22 |
|
2020-05-23 00:26:04 |
|
2018-10-13 00:22:58 |
|
2017-09-19 09:23:50 |
|
2016-04-26 19:56:19 |
|
2014-02-17 10:56:17 |
|
2014-01-19 21:26:56 |
|
2013-05-10 23:28:26 |
|