Vulnerability Name: | CVE-2010-2739 (CCN-60975) | ||||||||
Assigned: | 2010-08-07 | ||||||||
Published: | 2010-08-07 | ||||||||
Updated: | 2021-07-07 | ||||||||
Summary: | Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CONFIRM Type: Vendor Advisory http://blogs.technet.com/b/msrc/archive/2010/08/10/update-on-the-publicly-disclosed-win32k-sys-eop-vulnerability.aspx Source: MITRE Type: CNA CVE-2010-2739 Source: CCN Type: SA40870 Microsoft Windows win32k.sys Driver CreateDIBPalette() Buffer Overflow Source: SECUNIA Type: Vendor Advisory 40870 Source: CCN Type: Microsoft Web Site Microsoft Windows Source: CCN Type: OSVDB ID: 66934 Microsoft Windows win32k.sys CreateDIBPalette() Function Local Overflow Source: MISC Type: Exploit http://www.ragestorm.net/blogs/?p=255 Source: CCN Type: BID-42291 Microsoft Windows Kernel 'CreateDIBPalette()' Function Local Privilege Escalation Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2010-2029 Source: XF Type: UNKNOWN ms-win-createdibpallette-bo(60975) Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [08-06-2010] | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |