{
    "id": "CVE-2010-0425",
    "published": "2010-03-05 19:30:00",
    "last_modified": "2026-06-16 23:16:08",
    "cvss_score": "10.0",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
    "cwe": null,
    "description": "modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and \"orphaned callback pointers.\"",
    "epss_score": "0.94248",
    "epss_percentile": "0.99848",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:16:56",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "apache",
            "product": "http_server"
        },
        {
            "vendor": "broadcom",
            "product": "vmware_ace_management_server"
        },
        {
            "vendor": "ibm",
            "product": "http_server"
        },
        {
            "vendor": "ibm",
            "product": "websphere_application_server"
        },
        {
            "vendor": "microsoft",
            "product": "windows"
        },
        {
            "vendor": "oracle",
            "product": "http_server"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "11650",
            "title": "Apache 2.2.14 mod_isapi - Dangling Pointer Remote SYSTEM",
            "date": "2010-03-07",
            "url": "https://www.exploit-db.com/exploits/11650"
        }
    ],
    "refs_list": [
        "http://httpd.apache.org/security/vulnerabilities_20.html",
        "http://httpd.apache.org/security/vulnerabilities_22.html",
        "http://lists.vmware.com/pipermail/security-announce/2010/000105.html",
        "http://secunia.com/advisories/38978",
        "http://secunia.com/advisories/39628",
        "http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&r2=917869&pathrev=917870",
        "http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&r2=917869&pathrev=917870",
        "http://svn.apache.org/viewvc?view=revision&revision=917870",
        "http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447",
        "http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247",
        "http://www.kb.cert.org/vuls/id/280613",
        "http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html",
        "http://www.securityfocus.com/bid/38494",
        "http://www.securitytracker.com/id?1023701",
        "http://www.senseofsecurity.com.au/advisories/SOS-10-002",
        "http://www.vmware.com/security/advisories/VMSA-2010-0014.html",
        "http://www.vupen.com/english/advisories/2010/0634",
        "http://www.vupen.com/english/advisories/2010/0994",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/56624",
        "https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E"
    ]
}