← Back to browse · API

CVE-2010-2568

Severity
HIGH
CVSS
7.8
EPSS
0.91324
Risk score
56.96
CISA KEV
Yes
PoC
No
Published
2010-07-22
Modified
2025-10-22
First seen
2026-08-07
Aliases
EUVD-2010-2572, GHSA-6J7W-PXHR-G4PR
Products
Microsoft:Windows, n/a:n/a n/a
Sources
cisa.gov CVE-2010-2568
euvd EUVD-2010-2572

Description

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

References