The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: microsoft
Published: 2010-02-10T18:00:00
Updated: 2024-08-07T00:45:11.028Z
Reserved: 2010-01-07T00:00:00
Link: CVE-2010-0240
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-02-10T18:30:01.470
Modified: 2023-12-07T18:38:56.693
Link: CVE-2010-0240
Redhat
No data.