CVE-2010-3973 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 71.7% (pctl 99)
Patch early
A public exploit exists.
Description
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 71.74% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-12-23 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | wmi administrative tools |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft WMI Administration Tools - ActiveX Buffer Overflow (Metasploit) | 2011-01-14 |
| exploit-db | Microsoft WMITools - ActiveX Remote Command Execution | 2010-12-22 |
References
- http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx
- http://secunia.com/advisories/42693
- http://www.exploit-db.com/exploits/15809
- http://www.kb.cert.org/vuls/id/725596
- http://www.securityfocus.com/bid/45546
- http://www.vupen.com/english/advisories/2010/3301
- http://www.wooyun.org/bug.php?action=view&id=1006
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64250
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12475
- http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx
- http://secunia.com/advisories/42693
- http://www.exploit-db.com/exploits/15809
- http://www.kb.cert.org/vuls/id/725596
- http://www.securityfocus.com/bid/45546
- http://www.vupen.com/english/advisories/2010/3301
- http://www.wooyun.org/bug.php?action=view&id=1006
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64250
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12475
→ the Explorer · watch your stack · NVD