This may result in malicious or inadvertent altering of data on the server.'] Target Programs with Elevated Privileges ['This attack targets programs running with elevated privileges. Please address comments about this page to [email protected] There are NO warranties, implied or otherwise, with regard to this information or its use. BUGTRAQ:20100316 CORE-2009-0803: Virtual PC Hypervisor Memory Protection Vulnerability URL:http://www.securityfocus.com/archive/1/archive/1/510154/100/0/threaded MISC:http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug BID:38764 URL:http://www.securityfocus.com/bid/38764 SECTRACK:1023720 URL:http://securitytracker.com/id?1023720 Date Entry Created 20100401 Disclaimer: The entry creation date may reflect when the CVE-ID was allocated or

La notice d'information est disponible en téléchargement sur securityfocus.com Cette vulnérabilité est connue comme CVE-2010-1225. J. For More Information:[email protected] Back to top Use of the Common Vulnerabilities and Exposures List and the associated references from this Web site are subject to the Terms of Use. in future of trust in computing. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1225

application server) to execute based on the malicious configuration parameters. CVE and the CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. The goal is to gain access to, and perhaps modify, areas of the file system that the target software did not intend to be accessible.'] Accessing, Modifying or Executing Executable Files

La vulnerabilité a été publié en 01/04/2010 par Nicolas Economou avec CORE Security Technologies (confirmé).

https://cloud.google.com/ 18. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. no data from the host is exposed to the guest OS." 2 CVE-2009-1542 264 Exec Code +Priv 2009-07-15 2010-08-21 9.0 Admin Remote Low Single system Complete Complete Complete The Virtual Machine https://social.technet.microsoft.com/Forums/windows/en-US/3dbdea3f-04e4-40ab-97ae-07861b08b0cd/cve20101225?forum=w7itprovirt CoreLabs Information Security Advisories: https://www.coresecurity.com/grid/advisories Please Note: Since the websites are not hosted by Microsoft, the links may change without notice.

CVE-2017-0147 The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 https://cxsecurity.com/cveshow/CVE-2010-1225/

NIST CVE link : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1225

https://www.microsoft.com/en-au/download/details.aspx?id=3702

NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code

