PT-2010-2242 · Microsoft · Windows Server 2008+3
Tavis Ormandy
·
Published
2010-04-14
·
Updated
2025-01-21
·
CVE-2010-0481
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Vista versions Gold, SP1, and SP2
Windows Server 2008 versions Gold, SP2, and R2
Windows 7
Description
A denial of service issue exists due to the improper translation of a registry key's virtual path to its real path by the Windows kernel. This allows local users to cause a denial of service, resulting in a system reboot, via a crafted application. The vulnerability is related to how the kernel resolves the real path for a registry key from its virtual path, which can be exploited by running a specially crafted application, causing the system to become unresponsive and automatically restart.
Recommendations
For Windows Vista versions Gold, SP1, and SP2, update to a newer version to mitigate the risk.
For Windows Server 2008 versions Gold, SP2, and R2, update to a newer version to mitigate the risk.
For Windows 7, update to a newer version to mitigate the risk.
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 7
Windows Server 2008
Windows Vista