CVE-2010-0027
The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
- Affected products
- Internet Explorer, Windows, Windows 2000, Windows Server 2003, Windows Xp
- Microsoft Internet Explorer
- = 8, 8.0.6001
- Microsoft Windows 7
- All versions
- Microsoft Windows Server 2003
- All versions
- Microsoft Windows Server 2008
- All versions
- Microsoft Windows Vista
- All versions
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 34.0% (98th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2010-01-22
CVE-2010-0027 at NVD
3 known exploits for CVE-2010-0027
Proof-of-concept code and exploit modules indexed by Sploitus