CVE-2010-3970 (CNNVD-201012-288)
中文标题:
Microsoft Windows Shell图形处理器shimgvw.dll CreateSizedDIBSECTION函数栈缓冲区溢出漏洞
英文标题:
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shel...
漏洞描述
中文描述:
Microsoft Windows Shell图形处理器(graphics rendering engine)的shimgvw.dll中的CreateSizedDIBSECTION函数中存在基于栈的缓冲区溢出漏洞。远程攻击者可借助畸形的.MIC或包含带有负biClrUsed值缩略位图的未明Office文档执行任意代码。 该漏洞位于Microsoft Windows XP SP2和SP3版本,Server 2003 SP2版本,Vista SP1和SP2版本,以及Server 2008 Gold和SP2版本中。
英文描述:
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| microsoft | windows_server_2003 | * | - | - |
cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
|
| microsoft | windows_server_2008 | * | - | - |
cpe:2.3:o:microsoft:windows_server_2008:*:*:itanium:*:*:*:*:*
|
| microsoft | windows_server_2008 | - | - | - |
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:itanium:*:*:*:*:*
|
| microsoft | windows_vista | * | - | - |
cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*
|
| microsoft | windows_xp | * | - | - |
cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
|
| microsoft | windows_xp | - | - | - |
cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
exploitdb
exploitdb
cve.org
CVSS评分详情
AV:N/AC:M/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2010-3970 |
2025-11-11 15:18:18 | 2025-11-11 07:33:11 |
| NVD | nvd_CVE-2010-3970 |
2025-11-11 14:53:27 | 2025-11-11 07:41:59 |
| CNNVD | cnnvd_CNNVD-201012-288 |
2025-11-11 15:09:11 | 2025-11-11 07:49:47 |
| EXPLOITDB | exploitdb_EDB-16660 |
2025-11-11 15:05:53 | 2025-11-11 08:11:07 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 11 -> 14
- tags_count: 0 -> 5
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 缓冲区错误
- cnnvd_id: 未提取 -> CNNVD-201012-288
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.3
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 6
- data_sources: ['cve'] -> ['cve', 'nvd']