Skip to content

CVE-2010-2568

Improper Input Validation — is CVE-2010-2568real, exploitable, or a false positive? Here's the community ground truth.

High · CVSS 7.8EPSS 91.3%CISA KEVCWE-20 · Improper Input Validation

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

Published

Embed this verdict
TruePositive verdict for CVE-2010-2568
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2010-2568/badge.svg)](https://www.truepositive.app/cve/CVE-2010-2568)
HTML
<a href="https://www.truepositive.app/cve/CVE-2010-2568"><img src="https://www.truepositive.app/cve/CVE-2010-2568/badge.svg" alt="TruePositive verdict for CVE-2010-2568"></a>

Live badge — updates automatically as the community verdict changes.

Community ground truth

Community verdict

3 verdicts
Not a real issue

Includes TruePositive's curated baseline from public sources — community verdicts accrue on top.

to add your verdict.

Community real-world severity: High (High 3) — CVSS base score 7.8

In line with its CVSS base score.

Field notes & remediation

Verdicts are the quick signal — notes are the evidence and fixes behind them.

  • 0
    Field note · Marco FerriCurated

    Microsoft Windows Remote Code Execution Vulnerability — Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user. Listed in the CISA KEV catalog (added 2022-09-15) — confirmed exploited in the wild, not theoretical. FIRST EPSS puts the chance of exploitation in the next 30 days at ~91%. Treat it as real and prioritize remediation over triage.

  • 0
    Remediation · Waleed AzizCurated

    Required action for Microsoft Windows: Apply updates per vendor instructions. CISA set a federal remediation due date of 2022-10-06. After patching, verify the vulnerable path is no longer reachable before closing the finding.

Same weaknessCWE-20 · Improper Input Validation.