7.6
CVSSv2

CVE-2010-4701

Published: 20/01/2011 Updated: 19/09/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote malicious users to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows xp

microsoft windows 2003 server

microsoft windows 7

Exploits

<?php /* Microsoft Windows Fax Services Cover Page Editor (cov) Memory Corruption poc by Andrea Micalizzi aka rgod tested on: Microsoft Windows Server 2003 Standard Edition r2 sp2 all patched vulnerability: Microsoft Cover Page Editor (fxscoverexe, version 52 r2 (Build 3790srv03_sp2_gdr100216-1301: Service Pack 2) as included in the menti ...