Vulnerability Name: | CVE-2010-0478 (CCN-57329) | ||||||||
Assigned: | 2010-04-13 | ||||||||
Published: | 2010-04-13 | ||||||||
Updated: | 2019-04-30 | ||||||||
Summary: | Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
7.7 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0478 Source: CCN Type: SA39377 Microsoft Windows Media Services Buffer Overflow Vulnerability Source: CCN Type: Microsoft Security Bulletin MS10-025 Vulnerability in Microsoft Windows Media Services Could Allow Remote Code Execution (980858) Source: CCN Type: BID-39356 Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability Source: CERT Type: US Government Resource TA10-103A Source: MS Type: UNKNOWN MS10-025 Source: XF Type: UNKNOWN win-media-info-packet-bo(57329) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:7001 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |