PT-2010-5206 · Microsoft · Wmi Administrative Tools+2

牛奶坦克

·

Published

2010-12-23

·

Updated

2018-10-12

·

CVE-2010-3973

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft WMI Administrative Tools version 1.1 and earlier
Description A remote code execution issue exists in one of the Microsoft WMITools ActiveX controls, potentially allowing an attacker to execute arbitrary code via a crafted argument to the AddContextRef method. This could be related to an untrusted pointer dereference. An attacker could exploit this issue by constructing a specially crafted Web page. When a user views the Web page, the issue could allow remote code execution, potentially giving the attacker the same user rights as the logged-on user.
Recommendations For Microsoft WMI Administrative Tools version 1.1 and earlier, consider disabling the AddContextRef method in the WBEMSingleView.ocx ActiveX control as a temporary workaround until a patch is available. Restrict access to the WBEMSingleView.ocx control to minimize the risk of exploitation.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3973

Affected Products

Wmi Administrative Tools
Wbemsingleview.Ocx
Windows