CVE-2010-0242
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 65.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 65.83% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- microsoft/windows server 2008 · microsoft/windows vista
- Source
- secure@microsoft.com
References
- http://www.us-cert.gov/cas/techalerts/TA10-040A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-009
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8449
- http://www.us-cert.gov/cas/techalerts/TA10-040A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-009
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8449
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.