First published: Wed Feb 10 2010(Updated: )
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =gold | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows Vista | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0241 has a high severity rating due to its ability to allow remote code execution.
To fix CVE-2010-0241, ensure that you apply the security updates provided by Microsoft for the affected versions of Windows Vista and Windows Server 2008.
CVE-2010-0241 affects Microsoft Windows Vista and Windows Server 2008, specifically the Gold and SP2 versions.
CVE-2010-0241 involves remote attackers sending crafted ICMPv6 Route Information packets to exploit the vulnerability.
Yes, CVE-2010-0241 can be exploited remotely, allowing attackers to execute arbitrary code on the affected systems.