Vulnerability Name: | CVE-2010-3889 (CCN-62643) | ||||||||
Assigned: | 2010-10-08 | ||||||||
Published: | 2010-10-08 | ||||||||
Updated: | 2018-08-13 | ||||||||
Summary: | Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-3889 Source: MISC Type: UNKNOWN http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_ Source: CCN Type: eEye Digital Security 20100716 Stuxnet 0day Privilege Elevation Vulnerability #2 Source: MISC Type: UNKNOWN http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100716-(1) Source: CCN Type: Microsoft Web site Microsoft Windows Source: CCN Type: OSVDB ID: 68517 Microsoft Windows on 32-bit win32k.sys Keyboard Layout Loading Local Privilege Escalation Source: MISC Type: UNKNOWN http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061 Source: MISC Type: UNKNOWN http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities Source: MISC Type: UNKNOWN http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute7.xml Source: MISC Type: UNKNOWN http://www.virusbtn.com/conference/vb2010/abstracts/LastMinute8.xml Source: XF Type: UNKNOWN ms-win-unspec-privilege-esc(62643) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |