Vulnerability record · CVE-2010-0425 · published 5 March 2010
CVE-2010-0425: Apache mod_isapi on Windows remote code execution via orphaned callbacks
Ibm · Websphere Application Server
mod_isapi in Apache HTTP Server on Windows does not ensure request processing is complete before calling isapi_unload for an ISAPI .dll module, leaving orphaned callback pointers. A remote attacker can send a crafted request, including a reset packet, to trigger use of those stale pointers. The flaw affects Apache 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7 on Windows, and is rated CVSS 2.0 10.0.
Description
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score is 10.0 with network, unauthenticated, complete confidentiality, integrity, and availability impact, and EPSS is above the 99.8th percentile.
What it is
mod_isapi in Apache HTTP Server on Windows does not ensure request processing is complete before calling isapi_unload for an ISAPI .dll module, leaving orphaned callback pointers. A remote attacker can send a crafted request, including a reset packet, to trigger use of those stale pointers. The flaw affects Apache 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7 on Windows, and is rated CVSS 2.0 10.0.
Impact
Successful exploitation allows remote code execution in the context of the Apache HTTP Server process. That gives the attacker the server's privileges and any data or downstream access those privileges carry.
Attack surface
The vector is network-reachable (AV:N/AC:L/Au:N), so no authentication is required and no user interaction is indicated. It is limited to Windows deployments running mod_isapi with ISAPI modules loaded.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.94248 (99.845th percentile), indicating very high predicted exploitation activity. One reference carries an Exploit tag (SecurityFocus BID 38494), though the record does not confirm a public exploit's reliability or availability.
What to do
- Upgrade to a fixed Apache HTTP Server release: 2.0.64 or later on the 2.0 branch, 2.2.15 or later on the 2.2 branch, or 2.3.7 or later; apply the corresponding vendor updates for IBM WebSphere, Oracle, and VMware products listed.
- If mod_isapi is not required, disable it and remove ISAPI module mappings from the Windows configuration.
- Restrict network access to the HTTP service to trusted clients where operationally possible.
- Monitor vendor advisories for the listed products and apply their patched builds rather than relying on the Apache fix alone.
Detection
- Review Windows Apache error and access logs for crashes, restarts, or abnormal requests around ISAPI handler paths and .dll mappings.
- Alert on unexpected child process creation or command execution spawned by the Apache service account.
- Monitor for repeated connection resets or malformed requests targeting ISAPI-mapped URLs.
- Inventory Windows hosts running affected Apache versions and mod_isapi to confirm exposure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0425 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.