PT-2010-2242 · Microsoft · Windows Server 2008+3

Tavis Ormandy

·

Published

2010-04-14

·

Updated

2025-01-21

·

CVE-2010-0481

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Windows Vista versions Gold, SP1, and SP2 Windows Server 2008 versions Gold, SP2, and R2 Windows 7
Description A denial of service issue exists due to the improper translation of a registry key's virtual path to its real path by the Windows kernel. This allows local users to cause a denial of service, resulting in a system reboot, via a crafted application. The vulnerability is related to how the kernel resolves the real path for a registry key from its virtual path, which can be exploited by running a specially crafted application, causing the system to become unresponsive and automatically restart.
Recommendations For Windows Vista versions Gold, SP1, and SP2, update to a newer version to mitigate the risk. For Windows Server 2008 versions Gold, SP2, and R2, update to a newer version to mitigate the risk. For Windows 7, update to a newer version to mitigate the risk.

Fix

DoS

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2010-0481

Affected Products

Windows
Windows 7
Windows Server 2008
Windows Vista