CVE-2010-1889

HIGH

Microsoft Windows Server 2008 - Resource Management Error

Title source: rule
STIX 2.1

Description

Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tavis Ormandy · textdoswindows
https://www.exploit-db.com/exploits/14667

References (3)

Core 3
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-222A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11044

Scores

CVSS v3 7.8
EPSS 0.0094
EPSS Percentile 76.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-399
Status published
Products (2)
microsoft/windows_server_2008 (7 CPE variants)
microsoft/windows_vista (4 CPE variants)
Published Aug 11, 2010
Tracked Since Feb 18, 2026