CVE-2010-1263: Code Injection
Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; Microsoft Office XP SP3; Office 2003 SP3; and Office System 2007 SP1 and SP2 do not properly validate COM objects during instantiation, which allows remote attackers to execute arbitrary code via a crafted file, aka "COM Validation Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1263?
CVE-2010-1263 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2010-1263?
To mitigate CVE-2010-1263, it is recommended to apply the latest security updates from Microsoft for the affected Office products and Windows operating systems.
What software is affected by CVE-2010-1263?
CVE-2010-1263 affects Microsoft Office versions 2003, 2007, and Windows XP, Vista, Server 2003, and 7.
What type of vulnerability is CVE-2010-1263?
CVE-2010-1263 is classified as a COM object instantiation vulnerability.
Is CVE-2010-1263 exploitable without user interaction?
Yes, CVE-2010-1263 can be exploited remotely without the need for user interaction.