CVE-2010-0232 is a critical kernel vulnerability affecting numerous Microsoft Windows versions from NT 3.1 through Windows 7, including Server 2003 and 2008, when 16-bit application support is enabled. This flaw allows a local attacker to gain elevated privileges by manipulating BIOS calls and the VDM_TIB data structure, leading to improperly handled exceptions in the kernel's #GP trap handler. Rated with a CVSS score of 7.8 (HIGH), it presents a low-complexity attack vector (AV:L/AC:L) with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability is actively exploited, listed in CISA's KEV catalog, and has publicly available exploit modules in Metasploit and ExploitDB, indicating significant community attention and a high FAUCET Risk Score of 100/100.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:-:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.