peter bassill · operator
$ cve CVE-2010-0477 JSON

CVE-2010-0477 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 50.2% (pctl 99)

Patch early

A public exploit exists.

Description

The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS50.19% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2010-04-14
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftwindows 7
microsoftwindows server 2008

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD