CVE-2010-0425
published 2010-03-05CVE-2010-0425: modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on…
PriorityP275critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
94.25%
99.8th percentile
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.37 < 2.0.64 | 2.0.64 |
| apache | http_server | >= 2.2.0 < 2.2.15 | 2.2.15 |
| apache | http_server | >= 2.3.0 < 2.3.7 | 2.3.7 |
| broadcom | vmware_ace_management_server | < 2.7.2 | 2.7.2 |
| debian | apache2 | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit requires a TCP RST packet to trigger the DLL unload (use-after-free). Detect a pattern of: POST to ISAPI .dll endpoint → TCP RST from client → second POST to same ISAPI .dll endpoint within seconds. ↗
- →Alert on creation of 'sos.txt' in the Apache working directory as a post-exploitation indicator of successful shellcode execution. ↗
- →The vulnerability is Windows-only and affects mod_isapi. Scope detection to Apache on Windows with mod_isapi loaded and an ISAPI .dll configured. ↗
- →The exploit uses WSACancelBlockingCall() to force a TCP RST rather than a graceful close; network sensors should flag RST packets immediately following an incomplete HTTP POST to an ISAPI endpoint on port 80. ↗
- ·Exploitation requires an ISAPI module to be installed and configured on the target Apache server; the vulnerability is not reachable on default Apache installations without mod_isapi and a loaded ISAPI .dll. ↗
- ·Arbitrary code execution via this use-after-free has not been definitively proven in the wild; a real-world method requires a second ISAPI module to be loaded into the same memory region as the unloaded one. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_debian10.0LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wv6c-mphw-ggxf: modules/arch/win32/mod_isapi
ghsa_unreviewed·2022-05-02
CVE-2010-0425 [HIGH] GHSA-wv6c-mphw-ggxf: modules/arch/win32/mod_isapi
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
VMware
VMware Workstation, Player, and ACE address several security issues.
vendor_vmware·2010-09-23·CVSS 2.1
CVE-2010-0205 [LOW] VMware Workstation, Player, and ACE address several security issues.
VMSA-2010-0014: VMware Workstation, Player, and ACE address several security issues.
a. VMware Workstation and Player installer security issue The Workstation 7.x and Player 3.x installers will load an index.htm file located in the current working directory on which Workstation 7.x or Player 3.x is being installed. This may allow an attacker to display a malicious file if they manage to get their file onto the system prior to installation. The issue can only be exploited at the time that Workstation 7.x or Player 3.x is being installed. Installed versions of Workstation and Player are not affected. The security issue is no longer present in the installer of the new versions of Workstation 7.x and Player 3.x (see table below for the version numbers). The Common Vulnerabilities and Exposure
Debian
CVE-2010-0425: apache2 - modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 thr...
vendor_debian·2010·CVSS 10.0
CVE-2010-0425 [CRITICAL] CVE-2010-0425: apache2 - modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 thr...
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
Exploit-DB
Apache 2.2.14 mod_isapi - Dangling Pointer Remote SYSTEM
exploitdb·2010-03-07·CVSS 10.0
CVE-2010-0425 [CRITICAL] Apache 2.2.14 mod_isapi - Dangling Pointer Remote SYSTEM
Apache 2.2.14 mod_isapi - Dangling Pointer Remote SYSTEM
---
/*
* Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit (CVE-2010-0425)
* ------------------------------------------------------------------------------
*
* Advisory: http://www.senseofsecurity.com.au/advisories/SOS-10-002
*
* Description:
* pwn-isapi.cpp exploits a dangling pointer vulnerabilty in Apache 2.2.14 mod_isapi.
* Due to the nature of the vulnerability, and exploitation method, DEP should be limited to essential
* Windows programs and services. At worst, if DEP is enabled for the Apache process, you could cause
* a constant DoS by looping this (since apache will automatically restart) :)
*
* Note that the exploit code may need to be run multiple times before a shell is spawned (70%
* success rate - tested
Metasploit
Apache mod_isapi Dangling Pointer
metasploit
Apache mod_isapi Dangling Pointer
Apache mod_isapi Dangling Pointer
This module triggers a use-after-free vulnerability in the Apache Software Foundation mod_isapi extension for versions 2.2.14 and earlier. In order to reach the vulnerable code, the target server must have an ISAPI module installed and configured. By making a request that terminates abnormally (either an aborted TCP connection or an unsatisfied chunked request), mod_isapi will unload the ISAPI extension. Later, if another request comes for that ISAPI module, previously obtained pointers will be used resulting in an access violation or potentially arbitrary code execution. Although arbitrary code execution is theoretically possible, a real-world method of invoking this consequence has not been proven. In order to do so, one would need to find a situation w
No writeups or analysis indexed.
http://httpd.apache.org/security/vulnerabilities_20.htmlhttp://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000105.htmlhttp://secunia.com/advisories/38978http://secunia.com/advisories/39628http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&r2=917869&pathrev=917870http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&r2=917869&pathrev=917870http://svn.apache.org/viewvc?view=revision&revision=917870http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247http://www.kb.cert.org/vuls/id/280613http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.securityfocus.com/bid/38494http://www.securitytracker.com/id?1023701http://www.senseofsecurity.com.au/advisories/SOS-10-002http://www.vmware.com/security/advisories/VMSA-2010-0014.htmlhttp://www.vupen.com/english/advisories/2010/0634http://www.vupen.com/english/advisories/2010/0994https://exchange.xforce.ibmcloud.com/vulnerabilities/56624https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8439https://www.exploit-db.com/exploits/11650http://httpd.apache.org/security/vulnerabilities_20.htmlhttp://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000105.htmlhttp://secunia.com/advisories/38978http://secunia.com/advisories/39628http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&r2=917869&pathrev=917870http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&r2=917869&pathrev=917870http://svn.apache.org/viewvc?view=revision&revision=917870http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247http://www.kb.cert.org/vuls/id/280613http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.securityfocus.com/bid/38494http://www.securitytracker.com/id?1023701http://www.senseofsecurity.com.au/advisories/SOS-10-002http://www.vmware.com/security/advisories/VMSA-2010-0014.htmlhttp://www.vupen.com/english/advisories/2010/0634http://www.vupen.com/english/advisories/2010/0994https://exchange.xforce.ibmcloud.com/vulnerabilities/56624https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8439https://www.exploit-db.com/exploits/11650
2010-03-05
Published