CVE-2010-0812

Microsoft Windows XP-Server 2008 - Auth Bypass

Title source: llm
STIX 2.1

Description

Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7574
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39382
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-103A.html

Scores

EPSS 0.1745
EPSS Percentile 96.8%

Details

CWE
CWE-264
Status published
Products (5)
microsoft/windows_2003_server (2 CPE variants)
microsoft/windows_server_2003
microsoft/windows_server_2008 (6 CPE variants)
microsoft/windows_vista (6 CPE variants)
microsoft/windows_xp (3 CPE variants)
Published Apr 14, 2010
Tracked Since Feb 18, 2026