peter bassill · operator
$ cve CVE-2010-4701 JSON

CVE-2010-4701 EXPLOIT

7.6
HIGH · CVSS 2.0 · EPSS 47.8% (pctl 99)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.

Scoring

CVSS7.6 (HIGH, v2.0)
VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS47.83% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2011-01-20
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftwindows 2003 server
microsoftwindows 7
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD