ZeroHour

CVE-2010-0232

KEVmass

Local Privilege Escalation in Microsoft Windows Kernel (32-bit x86, 16-bit apps)

CISA: Microsoft Windows Kernel Exception Handler Vulnerability

CVSS
EPSS
29%p98
Published
KEV added
AI analysis

CVE-2010-0232 is a local privilege escalation flaw in the Microsoft Windows kernel: on 32-bit x86 platforms, the kernel does not properly validate certain BIOS calls made when 16-bit application support is enabled. A local attacker triggers the flaw by running a malicious 16-bit application on an affected 32-bit Windows system, causing the kernel to execute attacker-controlled code in kernel mode. Successful exploitation grants full elevated (kernel/SYSTEM-level) privileges, typically used as a post-compromise step after an attacker has already obtained local access. Any deployment running 32-bit x86 Windows with access to 16-bit applications enabled is affected, per CISA's listing of 'Microsoft Windows' (specific version ranges are not provided in the source data). The vulnerability was added to the CISA KEV catalog on 2022-03-03, confirming in-the-wild exploitation (ransomware use unknown), and its EPSS of 29.3% (98th percentile) indicates a high likelihood of exploitation over the next 30 days; no public PoC is known per the source data.

What to do: Apply Microsoft updates per vendor instructions (this CVE was addressed in Microsoft Security Bulletin MS10-021) on all 32-bit x86 Windows systems and verify remediation, per the CISA KEV required action. As an interim mitigation, disable access to 16-bit applications (e.g., via the 'Prevent access to 16-bit applications' policy) and restrict untrusted local logons on affected systems. Prioritize hosts where untrusted users can execute 16-bit programs.

Affected
Microsoft Windows
Estimated exposure
massmillions of legacy 32-bit Windows systems (the 32-bit x86 Windows installed base ran to hundreds of millions at 2010 disclosure; current unpatched count… — The flaw affects effectively every 32-bit x86 Windows system on which 16-bit application support is available — a default condition on such editions — and the historical installed base of 32-bit Windows was in the hundreds of millions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows
Weakness
CWE-264

In the news