CVE-2010-1256: Code Injection
Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1256?
CVE-2010-1256 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2010-1256?
To fix CVE-2010-1256, you should apply the latest security patches provided by Microsoft for IIS versions 6.0, 7.0, and 7.5.
What types of systems are affected by CVE-2010-1256?
CVE-2010-1256 affects Microsoft IIS versions 6.0, 7.0, and 7.5 when Extended Protection for Authentication is enabled.
Can unprivileged users exploit CVE-2010-1256?
Yes, CVE-2010-1256 allows remote authenticated users to exploit the vulnerability, potentially leading to arbitrary code execution.
What does the term 'memory corruption' mean in the context of CVE-2010-1256?
In the context of CVE-2010-1256, 'memory corruption' refers to the unintended overwrite of the memory, which can lead to system instability or hijacking by an attacker.