CVE-2010-3889
Summary
| CVE | CVE-2010-3889 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-10-08 22:00:37 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Virus Bulletin : VB2010 - Last-minute paper: An indepth look into Stuxnet | af854a3a-2127-422b-91ae-364da2661108 | www.virusbtn.com | |
| Is Stuxnet the 'best' malware ever? - Computerworld | af854a3a-2127-422b-91ae-364da2661108 | www.computerworld.com | |
| Myrtus and Guava, Episode MS10-061 - Securelist | af854a3a-2127-422b-91ae-364da2661108 | www.securelist.com | |
| Virus Bulletin : VB2010 - Last-minute paper: Unravelling Stuxnet | af854a3a-2127-422b-91ae-364da2661108 | www.virusbtn.com | |
| Security Webinars, Podcasts, Success Stories, White Papers, and Datasheets | eEye Digital Security | af854a3a-2127-422b-91ae-364da2661108 | www.eeye.com | |
| Stuxnet Using Three Additional Zero-Day Vulnerabilities | Symantec Connect | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | |
| Security Webinars, Podcasts, Success Stories, White Papers, and Datasheets | eEye Digital Security | MITRE | www.eeye.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.