CVE-2010-1256
high · 8.5Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."
8.5
CVSS
28.2%
EPSS (exploit prob.)
98th
EPSS percentile
2010-06-08
Published
AV:N/AC:M/Au:S/C:C/I:C/A:C
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_information_server | 6.0 |
| microsoft | windows_2003_server | all versions |
| microsoft | windows_2003_server | all versions |
| microsoft | windows_2003_server | all versions |
| microsoft | windows_vista | all versions |
| microsoft | windows_vista | all versions |
| microsoft | windows_vista | all versions |
| microsoft | windows_vista | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_7 | all versions |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2008 | r2 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/40573
- http://www.us-cert.gov/cas/techalerts/TA10-159B.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58864
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7149
- http://www.securityfocus.com/bid/40573
- http://www.us-cert.gov/cas/techalerts/TA10-159B.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58864
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7149
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-1256