{"api_version":"1","generated_at":"2026-07-23T10:18:50+00:00","cve":"CVE-2010-3889","urls":{"html":"https://cve.report/CVE-2010-3889","api":"https://cve.report/api/cve/CVE-2010-3889.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-3889","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-3889"},"summary":{"title":"CVE-2010-3889","description":"Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-10-08 22:00:37","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml","name":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Virus Bulletin : VB2010 - Last-minute paper: An indepth look into Stuxnet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_","name":"http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Is Stuxnet the 'best' malware ever? - Computerworld","mime":"application/octet-stream","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061","name":"http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Myrtus and Guava, Episode MS10-061 - Securelist","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml","name":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Virus Bulletin : VB2010 - Last-minute paper: Unravelling Stuxnet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-%281%29","name":"http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-%281%29","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Webinars, Podcasts, Success Stories, White Papers, and Datasheets | eEye Digital Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities","name":"http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Stuxnet Using Three Additional Zero-Day Vulnerabilities | Symantec Connect","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-(1)","name":"MISC:http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-(1)","refsource":"MITRE","tags":[],"title":"Security Webinars, Podcasts, Success Stories, White Papers, and Datasheets | eEye Digital Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-3889","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-3889","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"3889","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:26:12.174Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-%281%29"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-10-08T21:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml"},{"tags":["x_refsource_MISC"],"url":"http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-%281%29"},{"tags":["x_refsource_MISC"],"url":"http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities"},{"tags":["x_refsource_MISC"],"url":"http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_"},{"tags":["x_refsource_MISC"],"url":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml"},{"tags":["x_refsource_MISC"],"url":"http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-3889","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml","refsource":"MISC","url":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml"},{"name":"http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-(1)","refsource":"MISC","url":"http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-(1)"},{"name":"http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities","refsource":"MISC","url":"http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities"},{"name":"http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_","refsource":"MISC","url":"http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_"},{"name":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml","refsource":"MISC","url":"http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml"},{"name":"http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061","refsource":"MISC","url":"http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-3889","datePublished":"2010-10-08T21:00:00.000Z","dateReserved":"2010-10-08T00:00:00.000Z","dateUpdated":"2024-09-16T23:20:23.881Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-10-08 22:00:37","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"3889","Ordinal":"1","Title":"CVE-2010-3889","CVE":"CVE-2010-3889","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"3889","Ordinal":"1","NoteData":"Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.","Type":"Description","Title":"CVE-2010-3889"},{"CveYear":"2010","CveId":"3889","Ordinal":"2","NoteData":"2010-10-08","Type":"Other","Title":"Published"}]}}}