CVE-2010-2553

Microsoft Windows 7 - Code Injection

Title source: rule

Description

The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Cinepak Codec Decompression Vulnerability."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Abysssec · htmldoswindows
https://www.exploit-db.com/exploits/15122
exploitdb WORKING POC VERIFIED
by Abysssec · pythondoswindows
https://www.exploit-db.com/exploits/15112
nomisec WRITEUP
by Sunqiz · poc
https://github.com/Sunqiz/cve-2010-2553-reproduction

Scores

EPSS 0.6844
EPSS Percentile 98.6%

Details

CWE
CWE-94
Status published
Products (3)
microsoft/windows_7 (2 CPE variants)
microsoft/windows_vista (4 CPE variants)
microsoft/windows_xp (2 CPE variants)
Published Aug 11, 2010
Tracked Since Feb 18, 2026