Junglewise Threat Intelligence

CVE-2010-0232: Microsoft Windows Kernel Exception Handler Vulnerability

CVE-2010-0232 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Windows 2000, Microsoft Windows, Microsoft Windows Server 2003, Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows XP, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

The Microsoft Windows kernel fails to properly validate BIOS calls when 16-bit application support is enabled on 32-bit x86 platforms. Local attackers can exploit this by crafting a VDM_TIB data structure and calling NtVdmControl to trigger an improperly handled exception in the #GP trap handler (nt!KiTrap0D), resulting in local privilege escalation.

Affected products

  • Microsoft Windows NT 3.1
  • Microsoft Windows 2000 SP4
  • Microsoft Windows XP SP2, SP3
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista Gold, SP1, SP2
  • Microsoft Windows Server 2008 Gold, SP2
  • Microsoft Windows 7

Timeline

  • 2010-01-20: advisory: Initial Microsoft security advisory released
  • 2010-02-09: patched: Microsoft released MS10-015 to address the vulnerability
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats