CVE-2010-1893

Windows 7, Windows Server 2008, and Windows Vista - Local Privilege Escalation via TCP/IP Stack Integer Overflow

Title source: llm
STIX 2.1

Description

Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."

References (3)

Core 3
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-222A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12087

Scores

EPSS 0.0132
EPSS Percentile 68.1%

Details

CWE
CWE-189
Status published
Products (3)
microsoft/windows_7 (2 CPE variants)
microsoft/windows_server_2008 (5 CPE variants)
microsoft/windows_vista
Published Aug 11, 2010
Tracked Since Feb 18, 2026