CVE-2010-3973

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
23/12/2010
Last modified:
11/04/2025

Description

The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:wmi_administrative_tools:*:*:*:*:*:*:*:* 1.1 (including)