Junglewise Threat Intelligence

CVE-2010-0806: Microsoft Windows buffer overflow in Server service

CVE-2010-0806 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-05-20

Technologies: Adobe Acrobat, Adobe Reader, Microsoft Windows, Microsoft Defender, Microsoft Internet Explorer. Vendors: Adobe, Microsoft.

Executive brief

CISA has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, including legacy flaws in Windows and Internet Explorer as well as modern issues in Microsoft Defender. These vulnerabilities are being actively used by attackers to gain unauthorized access, escalate privileges, or disrupt services. Organizations should prioritize patching these specific flaws to prevent potential data breaches or system outages.

Technical details

This advisory covers seven distinct vulnerabilities added to the CISA KEV catalog due to active exploitation. The flaws include a remote code execution buffer overflow in the Windows Server service (CVE-2008-4250), memory corruption issues in DirectX and Internet Explorer (CVE-2009-1537, CVE-2010-0249, CVE-2010-0806), and a heap overflow in Adobe Acrobat/Reader (CVE-2009-3459). Additionally, two modern vulnerabilities in Microsoft Defender allow for elevation of privilege (CVE-2026-41091) and denial of service (CVE-2026-45498). Attack vectors range from network-based remote exploitation to local privilege escalation. Remediation should follow vendor-specific security updates.

Affected products

  • Microsoft Windows
  • Microsoft DirectX
  • Adobe Acrobat
  • Adobe Reader
  • Microsoft Internet Explorer
  • Microsoft Defender

CVE identifiers

  • CVE-2010-0806
  • CVE-2009-1537
  • CVE-2009-3459
  • CVE-2008-4250
  • CVE-2026-41091
  • CVE-2010-0249
  • CVE-2026-45498

Timeline

  • 2026-05-20: advisory: CISA published the alert and added vulnerabilities to the KEV catalog.
  • 2026-05-20: exploited: CISA confirmed evidence of active exploitation for these vulnerabilities.

References