peter bassill · operator
$ cve CVE-2010-3973 JSON

CVE-2010-3973 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 71.7% (pctl 99)

Patch early

A public exploit exists.

Description

The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS71.74% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2010-12-23
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftwmi administrative tools

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD