CVE-2010-2550: Input Validation
The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2550?
CVE-2010-2550 has a critical severity rating, allowing remote code execution through crafted SMB packets.
How do I fix CVE-2010-2550?
To fix CVE-2010-2550, apply the security updates released by Microsoft for the affected versions of Windows.
Which versions of Windows are affected by CVE-2010-2550?
CVE-2010-2550 affects Microsoft Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows 7.
Can CVE-2010-2550 be exploited remotely?
Yes, attackers can exploit CVE-2010-2550 remotely by sending a specially crafted SMB request.
What type of vulnerability is CVE-2010-2550 classified as?
CVE-2010-2550 is classified as a remote code execution vulnerability in the SMB Server.