CVE-2010-2568

Confirmed PUBLISHED

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote...

Vendor: Microsoft Product: Windows
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High EPSS 91.3%

At a Glance

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

metasploit windows cisa
CVE Published
Jul 22, 2010
Exploitation Reported
Sep 15, 2022
CVSS
7.8 High
EPSS
91.3%
Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • MS10-046 docs.microsoft.com · Vendor Advisory https://docs.microsoft.com/en-us/security-updates/securitybulletins/2...
  • TA10-222A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA10-222A.html
  • VU#940193 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/940193
  • 40647 secunia.com · Third-Party Advisory http://secunia.com/advisories/40647
  • oval:org.mitre.oval:def:11564 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
Show 9 more references