CVE-2010-0476 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 34.3% (pctl 98)
Patch early
A public exploit exists.
Description
The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 34.33% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-399 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-04-14 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| microsoft | windows 2003 server |
| microsoft | windows 7 |
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
| microsoft | windows vista |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows 7/2008 R2 - SMB Client Trans2 Stack Overflow (MS10-020) (PoC) | 2010-04-17 |
References
- http://secunia.com/advisories/39372
- http://www.securityfocus.com/bid/39336
- http://www.us-cert.gov/cas/techalerts/TA10-103A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-020
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6918
- http://secunia.com/advisories/39372
- http://www.securityfocus.com/bid/39336
- http://www.us-cert.gov/cas/techalerts/TA10-103A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-020
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6918
→ the Explorer · watch your stack · NVD