CVE-2010-2568 is a critical vulnerability affecting Windows Shell in various Microsoft Windows operating systems, including XP, Server 2003, Vista, Server 2008, and Windows 7. This flaw allows local or remote attackers to execute arbitrary code by crafting malicious .LNK or .PIF shortcut files, which are improperly handled during icon display in Windows Explorer. With a CVSS score of 7.8 (High), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. It is actively exploited, notably leveraged in the Stuxnet attacks, with multiple Metasploit modules and ExploitDB entries available, and has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:itanium:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.