← back
CVE-2010-0425

CVE-2010-0425

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 94%
from disclosure to weapon0 days
Published on NVDMar 5
metasploitMar 5
exploitation probability
94%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.