Improper input validation in Microsoft Windows and Windows Server - CVE-2010-2568
Published: January 3, 2017 / Updated: September 16, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to an error when parsing icons to .lnk and .pif files within Windows Explorer. A remote attacker can create a specially crafted icon file, trick the victim into clicking on it and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of the vulnerability results in compromise of vulnerable system.
Note: this vulnerability is being actively exploited.
Affected software
Windows Server
How to mitigate CVE-2010-2568
Links to Public Exploits and PoC-codes
- Exploit #5078 - FannyBMP or DementiaWheel Detection Registry Check (January 25, 2021)
- Exploit #687 - Microsoft Windows - Shell LNK Code Execution (MS10-046) (Metasploit) (March 18, 2020)
- Exploit #688 - Microsoft Windows - Automatic LNK Shortcut File Code Execution (March 18, 2020)
- Exploit #1595 - Microsoft Windows Shell LNK Code Execution (March 18, 2020)
- Exploit #1672 - Microsoft Windows Shell LNK Code Execution (March 18, 2020)