Vulnerability Description
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Wmi Administrative Tools | <= 1.1 |
Related Weaknesses (CWE)
References
- http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-i
- http://secunia.com/advisories/42693Vendor Advisory
- http://www.exploit-db.com/exploits/15809Exploit
- http://www.kb.cert.org/vuls/id/725596US Government Resource
- http://www.securityfocus.com/bid/45546Exploit
- http://www.vupen.com/english/advisories/2010/3301Vendor Advisory
- http://www.wooyun.org/bug.php?action=view&id=1006Exploit
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-02
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64250
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-i
- http://secunia.com/advisories/42693Vendor Advisory
- http://www.exploit-db.com/exploits/15809Exploit
- http://www.kb.cert.org/vuls/id/725596US Government Resource
- http://www.securityfocus.com/bid/45546Exploit
FAQ
What is CVE-2010-3973?
CVE-2010-3973 is a vulnerability with a CVSS score of 9.3 (HIGH). The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary co...
How severe is CVE-2010-3973?
CVE-2010-3973 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3973?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Wmi Administrative Tools.