SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2010-2568

Microsoft Windows Remote Code Execution Vulnerability

KEVHIGH 7.8EPSS 91.3%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 October 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
91.32% probability · 100th percentile
CISA KEV
Listed 15 September 2022 · due 6 October 2022
Affected
microsoft/windows 7 · microsoft/windows server 2003 · microsoft/windows server 2008 · microsoft/windows vista · microsoft/windows xp
Source
secure@microsoft.com

CISA notes

Apply updates per vendor instructions. https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-046; https://nvd.nist.gov/vuln/detail/CVE-2010-2568

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.