vendor:
Windows
by:
Skypher
9,3
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Windows
Affected Version From: Windows XP
Affected Version To: Windows Vista
Patch Exists: YES
Related CWE: CVE-2010-1885
CPE: o:microsoft:windows
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2010
MS10-051
MS10-051 is a buffer overflow vulnerability in the Windows HTTP service. It allows an attacker to execute arbitrary code on the target system by sending a specially crafted HTTP request. The vulnerability affects Windows XP, Windows Server 2003, and Windows Vista. The exploit code is written in Python and uses a socket to connect to the target system and send the malicious request.
Mitigation:
Microsoft has released a patch for this vulnerability.