9.3
CVSSv2

CVE-2010-0027

Published: 22/01/2010 Updated: 07/12/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote malicious users to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet_explorer 8

microsoft internet_explorer 8.0.6001

microsoft windows_7 -

microsoft windows_server_2003

microsoft windows_server_2008

microsoft windows_vista

microsoft windows_xp

microsoft windows_xp -

microsoft internet_explorer 7

microsoft internet_explorer 7.0

microsoft internet_explorer 7.0.5730

microsoft internet_explorer 7.0.5730.11

microsoft internet_explorer 7.00.5730.1100

microsoft internet_explorer 7.00.6000.16386

microsoft internet_explorer 7.00.6000.16441

microsoft internet explorer 6

microsoft internet explorer 5.01

microsoft windows xp

microsoft windows xp -

microsoft windows 2000

microsoft windows server 2003

microsoft windows 2003 server

Exploits

source: wwwsecurityfocuscom/bid/37884/info Microsoft Internet Explorer is prone to a remote code-execution vulnerability Attackers can exploit this issue to execute arbitrary code in the context of the user running the application Successful exploits will compromise the application and possibly the computer NOTE: Reports indicate tha ...