CVE-2010-3972

Description

Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted FTP command, aka IIS FTP Service Heap Buffer Overrun Vulnerability. NOTE: some of these details are obtained from third party information.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
91.689

Associated Vulnerability

VulnerabilityOS Platform
ms11-004: vulnerability in internet information services (iis) ftp service could allow remote code execution for Windows 7 (KB2489256) x86 based systemsWindows
ms11-004: vulnerability in internet information services (iis) ftp service could allow remote code execution for Windows 7 (KB2489256) x86 based systems for SP1Windows
ms11-004: vulnerability in internet information services (iis) ftp service could allow remote code execution for Windows 7 for x64-based Systems (KB2489256)Windows
ms11-004: vulnerability in internet information services (iis) ftp service could allow remote code execution for Windows 7 for x64-based Systems (KB2489256) for SP1Windows
ms11-004: vulnerability in internet information services (iis) ftp service could allow remote code execution for Windows Server 2008 R2 x64 Edition (KB2489256)Windows
ms11-004: vulnerability in internet information services (iis) ftp service could allow remote code execution for Windows Server 2008 R2 x64 Edition (KB2489256) for SP1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-12256Security Update for Windows 7 (KB2489256)
PATCH-12257Security Update for Windows 7 (KB2489256)
PATCH-12258Security Update for Windows 7 for x64-based Systems (KB2489256)
PATCH-12259Security Update for Windows 7 for x64-based Systems (KB2489256)
PATCH-12260Security Update for Windows Server 2008 R2 x64 Edition (KB2489256)
PATCH-12261Security Update for Windows Server 2008 R2 x64 Edition (KB2489256)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234