← Back

CVE-2010-1256

nvd nist
Published: Jun 8, 2010Modified: Apr 29, 2026

JSON object

Loading...
8.5
Vector
AV:N/AC:M/Au:S/C:C/I:C/A:C
Exploitability: 6.8 / Impact: 10.0
Source: NVD

Description

Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."

Affected (1)

1 product
Internet Information Server
Configuration A
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Version 6.0
Running on/withPlatform Versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows 2003 Server
All versions
Configuration B
4 platform
Running on/withPlatform Versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Vista
All versions
Configuration C
6 platform
Running on/withPlatform Versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Configuration D
3 platform
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows Server 2008
Version r2
Microsoft
Windows Server 2008
Version r2

Timeline

No history available yet.