CVE-2010-2739
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.7%
from disclosure to weapon0 days
Published on NVDSep 7
1st PoCAug 6
exploitation probability
3.7%top 11% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/14566⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://blogs.technet.com/b/msrc/archive/2010/08/10/update-on-the-publicly-disclosed-win32k-sys-eop-vulnerability.aspxhttp://secunia.com/advisories/40870https://msrc.microsoft.com/blog/2010/08/update-on-the-publicly-disclosed-win32k-sys-eop-vulnerability/http://www.ragestorm.net/blogs/?p=255http://www.vupen.com/english/advisories/2010/2029