Vulnerability Name: | CVE-2010-2566 (CCN-60718) | ||||||||
Assigned: | 2010-08-10 | ||||||||
Published: | 2010-08-10 | ||||||||
Updated: | 2019-02-26 | ||||||||
Summary: | The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-2566 Source: CCN Type: SA40879 Microsoft Windows SChannel Two Vulnerabilities Source: CCN Type: SA40883 Microsoft Windows TLS/SSL Session Renegotiation Plaintext Injection Vulnerability Source: CCN Type: Microsoft Security Bulletin MS12-006 Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) Source: CCN Type: Microsoft Security Bulletin MS12-049 Vulnerability in TLS Could Allow Information Disclosure (2655992) Source: CCN Type: Microsoft Security Bulletin MS14-066 Vulnerability in Schannel Could Allow Remote Code Execution (2992611) Source: CCN Type: Microsoft Security Bulletin MS10-049 Vulnerabilities in SChannel could allow Remote Code Execution (980436) Source: CCN Type: Microsoft Security Bulletin MS10-085 Vulnerabilities in SChannel Could Allow Denial of Service (2207566) Source: CCN Type: BID-42246 Microsoft Windows SChannel Certificate Request Remote Code Execution Vulnerability Source: CERT Type: US Government Resource TA10-222A Source: MS Type: UNKNOWN MS10-049 Source: XF Type: UNKNOWN ms-win-schannel-code-execution(60718) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11787 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |