CVE-2010-2550
The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
- Affected products
- Windows, Windows 7, Windows Server 2003, Windows Server 2008, Windows Vista, Windows Xp
- Microsoft Windows 2003 Server
- All versions
- Microsoft Windows 7
- All versions
- Microsoft Windows Server 2003
- All versions
- Microsoft Windows Server 2008
- All versions
- Microsoft Windows Vista
- All versions
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 75.7% (99th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2010-08-11
CVE-2010-2550 at NVD
4 known exploits for CVE-2010-2550
Proof-of-concept code and exploit modules indexed by Sploitus