4.9
CVE-2010-1735
- EPSS 2.49%
- Veröffentlicht 06.05.2010 12:47:23
- Zuletzt bearbeitet 16.06.2026 23:19:13
- Erkennungen
The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update -
Microsoft ≫ Windows 2000 Update beta3
Microsoft ≫ Windows 2000 Update gold
Microsoft ≫ Windows 2000 Update rc1
Microsoft ≫ Windows 2000 Update rc2
Microsoft ≫ Windows 2000 Update sp1
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Update sp3
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2000 Version -
Microsoft ≫ Windows 2003 Server Update gold
Microsoft ≫ Windows 2003 Server Update gold Edition itanium
Microsoft ≫ Windows 2003 Server Update gold Edition x64
Microsoft ≫ Windows 2003 Server Update r2 Edition x64
Microsoft ≫ Windows 2003 Server Update sp1
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
Microsoft ≫ Windows Server 2003 Update -
Microsoft ≫ Windows Server 2003 Update sp1
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Xp Edition x86
Microsoft ≫ Windows Xp Update gold
Microsoft ≫ Windows Xp Update gold Edition embedded
Microsoft ≫ Windows Xp Update gold Edition media_center
Microsoft ≫ Windows Xp Update gold Edition professional
Microsoft ≫ Windows Xp Update gold Edition tablet_pc
Microsoft ≫ Windows Xp Update sp1
Microsoft ≫ Windows Xp Update sp1 Edition embedded
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp1 Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition tablet_pc
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp2 Edition embedded
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition professional
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
Microsoft ≫ Windows Xp Update sp2 Edition x86
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Update sp3 Edition x86
Microsoft ≫ Windows Xp Version -
Microsoft ≫ Windows Xp Version - Update gold Edition 64-bit-2002
Microsoft ≫ Windows Xp Version - Update gold Edition 64-bit-2003
Microsoft ≫ Windows Xp Version - Update gold Edition home
Microsoft ≫ Windows Xp Version - Update gold Edition x64
Microsoft ≫ Windows Xp Version - Update sp1 Edition home
Microsoft ≫ Windows Xp Version - Update sp2 Edition home
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Windows Xp Version - Update sp3 Edition embedded
Microsoft ≫ Windows Xp Version - Update sp3 Edition home
Microsoft ≫ Windows Xp Version - Update sp3 Edition media_center
Microsoft ≫ Windows Xp Version - Update sp3 Edition professional
Microsoft ≫ Windows Xp Version - Update sp3 Edition tablet_pc
Microsoft ≫ Windows Xp Version sp3
Microsoft ≫ Windows Xp Version sp3 Update unknown Edition english
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.49% | 0.826 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://secunia.com/advisories/39456
http://vigilance.fr/vulnerability/Windows-denials-of-service-of-win32k-sys-9607
http://www.securityfocus.com/archive/1/510884/100/0/threaded
http://www.securityfocus.com/bid/39630