4.9

CVE-2010-1735

Exploit

The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 2000 Update-
MicrosoftWindows 2000 Updatebeta3
MicrosoftWindows 2000 Updategold
MicrosoftWindows 2000 Updaterc1
MicrosoftWindows 2000 Updaterc2
MicrosoftWindows 2000 Updatesp1
MicrosoftWindows 2000 Updatesp2
MicrosoftWindows 2000 Updatesp3
MicrosoftWindows 2000 Updatesp4
MicrosoftWindows 2000 Version-
MicrosoftWindows 2003 Server Updategold Editionitanium
MicrosoftWindows 2003 Server Updategold Editionx64
MicrosoftWindows 2003 Server Updater2 Editionx64
MicrosoftWindows 2003 Server Updatesp2 Editionitanium
MicrosoftWindows Xp Editionx86
MicrosoftWindows Xp Updategold
MicrosoftWindows Xp Updategold Editionembedded
MicrosoftWindows Xp Updategold Editionmedia_center
MicrosoftWindows Xp Updategold Editionprofessional
MicrosoftWindows Xp Updategold Editiontablet_pc
MicrosoftWindows Xp Updatesp1
MicrosoftWindows Xp Updatesp1 Editionembedded
MicrosoftWindows Xp Updatesp1 Editionmedia_center
MicrosoftWindows Xp Updatesp1 Editionprofessional
MicrosoftWindows Xp Updatesp1 Editiontablet_pc
MicrosoftWindows Xp Updatesp2
MicrosoftWindows Xp Updatesp2 Editionembedded
MicrosoftWindows Xp Updatesp2 Editionmedia_center
MicrosoftWindows Xp Updatesp2 Editionprofessional
MicrosoftWindows Xp Updatesp2 Editiontablet_pc
MicrosoftWindows Xp Updatesp2 Editionx86
MicrosoftWindows Xp Updatesp3
MicrosoftWindows Xp Updatesp3 Editionx86
MicrosoftWindows Xp Version-
MicrosoftWindows Xp Version- Updategold Edition64-bit-2002
MicrosoftWindows Xp Version- Updategold Edition64-bit-2003
MicrosoftWindows Xp Version- Updategold Editionhome
MicrosoftWindows Xp Version- Updategold Editionx64
MicrosoftWindows Xp Version- Updatesp1 Editionhome
MicrosoftWindows Xp Version- Updatesp2 Editionhome
MicrosoftWindows Xp Version- Updatesp2 Editionx64
MicrosoftWindows Xp Version- Updatesp3
MicrosoftWindows Xp Version- Updatesp3 Editionembedded
MicrosoftWindows Xp Version- Updatesp3 Editionhome
MicrosoftWindows Xp Version- Updatesp3 Editionmedia_center
MicrosoftWindows Xp Version- Updatesp3 Editionprofessional
MicrosoftWindows Xp Version- Updatesp3 Editiontablet_pc
MicrosoftWindows Xp Versionsp3
MicrosoftWindows Xp Versionsp3 Updateunknown Editionenglish
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.88% 0.746
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.