CVE-2010-1256
Summary
| CVE | CVE-2010-1256 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-08 20:30:00 UTC |
| Updated | 2023-12-07 18:38:00 UTC |
| Description | Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability." |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Information Server | 6.0 | All | All | All |
| Application | Microsoft | Internet Information Server | 6.0 | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | itanium | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | itanium | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows 7 | - | All | All | All |
| Operating System | Microsoft | Windows 7 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | x32 | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x32 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | All | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | All | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | x32 | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x32 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | All | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | All | x64 | All |
| Operating System | Microsoft | Windows Vista | All | sp1 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp1 | x64 | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Vista | - | sp1 | All | All |
| Operating System | Microsoft | Windows Vista | - | sp2 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp1 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp1 | x64 | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Vista | - | sp1 | All | All |
| Operating System | Microsoft | Windows Vista | - | sp2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft IIS Authentication Remote Code Execution Vulnerability | BID | www.securityfocus.com | |
| Microsoft Security Bulletin MS10-040 - Important | Microsoft Docs | MS | docs.microsoft.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| US-CERT Technical Cyber Security Alert TA10-159B -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.