CVE-2010-0425

Description

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and orphaned callback pointers.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
86.822

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.14Windows
Update Apache to version 2.0.64Windows
Vulnerabilities CVE-2010-0425 are fixed in Apache 2.2.15Windows
Vulnerabilities CVE-2010-0425 are fixed in Apache 2.0.64Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 5.0Windows
Update Apache to version 2.2.14 (For Linux)Linux
Update Apache to version 2.0.64 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234