Vulnerability Name: | CVE-2010-3888 (CCN-62642) | ||||||||
Assigned: | 2010-10-08 | ||||||||
Published: | 2010-10-08 | ||||||||
Updated: | 2010-10-11 | ||||||||
Summary: | Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-3888 Source: MISC Type: UNKNOWN http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_ Source: MISC Type: UNKNOWN http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716 Source: CCN Type: eEye Digital Security 20100716 Stuxnet 0day Privilege Elevation Vulnerability #2 Source: CCN Type: Microsoft Web site Microsoft Windows Source: MISC Type: UNKNOWN http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061 Source: CCN Type: BID-44357 Microsoft Windows Kernel Task Scheduler Service Local Privilege Escalation Vulnerability Source: MISC Type: UNKNOWN http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities Source: MISC Type: UNKNOWN http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml Source: MISC Type: UNKNOWN http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml Source: XF Type: UNKNOWN ms-win-unspec-priv-esc(62642) Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [11-20-2010] | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |