Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-0232

89
FAUCET Score

CVE-2010-0232 is a critical kernel vulnerability affecting numerous Microsoft Windows versions from NT 3.1 through Windows 7, including Server 2003 and 2008, when 16-bit application support is enabled. This flaw allows a local attacker to gain elevated privileges by manipulating BIOS calls and the VDM_TIB data structure, leading to improperly handled exceptions in the kernel's #GP trap handler. Rated with a CVSS score of 7.8 (HIGH), it presents a low-complexity attack vector (AV:L/AC:L) with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability is actively exploited, listed in CISA's KEV catalog, and has publicly available exploit modules in Metasploit and ExploitDB, indicating significant community attention and a high FAUCET Risk Score of 100/100.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:x86:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:-:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
29.25%
Probability of exploitation in next 30 days
EPSS Percentile
98.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Mar 3, 2022
Metasploit: Windows SYSTEM Escalation via KiTrap0D · Jan 19, 2010
ExploitDB: EDB-11199 · Jan 19, 2010
This CVE's current EPSS score of 0.2925 is in the 100th percentile among its peer group of 16,985 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

microsoftpatch availablevia nvd_reference
View patch

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
blogs.technet.com / msrc/archive/2010/01/20/security-advisory-979682-released.aspx
Broken Link
lists.immunitysec.com / pipermail/dailydave/2010-January/006000.html
Broken Link
lock.cmpxchg8b.com / c0af0967d904cef2ad4db766a00bc6af/KiTrap0D.zip
Broken LinkExploit
docs.microsoft.com / en-us/security-updates/securitybulletins/2010/ms10-015
PatchVendor Advisory
seclists.org / fulldisclosure/2010/Jan/341
ExploitMailing ListThird Party Advisory
secunia.com / advisories/38265
Broken LinkVendor Advisory
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/55742
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8344
Broken Link
microsoft.com / technet/security/advisory/979682.mspx
Broken LinkPatchVendor Advisory
securityfocus.com / archive/1/509106/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/37864
Broken LinkExploitThird Party AdvisoryVDB Entry
us-cert.gov / cas/techalerts/TA10-040A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2010/0179
Broken LinkVendor Advisory