← Vulnerability feed

Vulnerability record · CVE-2010-0425 · published 5 March 2010

CVE-2010-0425: Apache mod_isapi on Windows remote code execution via orphaned callbacks

Ibm · Websphere Application Server

mod_isapi in Apache HTTP Server on Windows does not ensure request processing is complete before calling isapi_unload for an ISAPI .dll module, leaving orphaned callback pointers. A remote attacker can send a crafted request, including a reset packet, to trigger use of those stale pointers. The flaw affects Apache 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7 on Windows, and is rated CVSS 2.0 10.0.

10.0 CVSS 2.0 High EPSS 94% · top 0.2%
10.0CVSS 2.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
84References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score is 10.0 with network, unauthenticated, complete confidentiality, integrity, and availability impact, and EPSS is above the 99.8th percentile.

What it is

mod_isapi in Apache HTTP Server on Windows does not ensure request processing is complete before calling isapi_unload for an ISAPI .dll module, leaving orphaned callback pointers. A remote attacker can send a crafted request, including a reset packet, to trigger use of those stale pointers. The flaw affects Apache 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7 on Windows, and is rated CVSS 2.0 10.0.

Impact

Successful exploitation allows remote code execution in the context of the Apache HTTP Server process. That gives the attacker the server's privileges and any data or downstream access those privileges carry.

Attack surface

The vector is network-reachable (AV:N/AC:L/Au:N), so no authentication is required and no user interaction is indicated. It is limited to Windows deployments running mod_isapi with ISAPI modules loaded.

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.94248 (99.845th percentile), indicating very high predicted exploitation activity. One reference carries an Exploit tag (SecurityFocus BID 38494), though the record does not confirm a public exploit's reliability or availability.

What to do

  • Upgrade to a fixed Apache HTTP Server release: 2.0.64 or later on the 2.0 branch, 2.2.15 or later on the 2.2 branch, or 2.3.7 or later; apply the corresponding vendor updates for IBM WebSphere, Oracle, and VMware products listed.
  • If mod_isapi is not required, disable it and remove ISAPI module mappings from the Windows configuration.
  • Restrict network access to the HTTP service to trusted clients where operationally possible.
  • Monitor vendor advisories for the listed products and apply their patched builds rather than relying on the Apache fix alone.

Detection

  • Review Windows Apache error and access logs for crashes, restarts, or abnormal requests around ISAPI handler paths and .dll mappings.
  • Alert on unexpected child process creation or command execution spawned by the Apache service account.
  • Monitor for repeated connection resets or malformed requests targeting ISAPI-mapped URLs.
  • Inventory Windows hosts running affected Apache versions and mod_isapi to confirm exposure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://httpd.apache.org/security/vulnerabilities_20.html Vendor Advisory
http://httpd.apache.org/security/vulnerabilities_22.html Vendor Advisory
http://lists.vmware.com/pipermail/security-announce/2010/000105.html Broken Link
http://secunia.com/advisories/38978 Broken Link
http://secunia.com/advisories/39628 Broken Link
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&r2=917869&pathrev=917870 Permissions Required
http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&r2=917869&pathrev=917870 Permissions Required
http://svn.apache.org/viewvc?view=revision&revision=917870 Permissions Required
http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247 Third Party Advisory
http://www.kb.cert.org/vuls/id/280613 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html Third Party Advisory
http://www.securityfocus.com/bid/38494 Broken LinkExploit
http://www.securitytracker.com/id?1023701 Broken Link
http://www.senseofsecurity.com.au/advisories/SOS-10-002 Third Party AdvisoryURL Repurposed
http://www.vmware.com/security/advisories/VMSA-2010-0014.html Third Party Advisory
http://www.vupen.com/english/advisories/2010/0634 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2010/0994 Broken LinkIssue TrackingMailing ListVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/56624 Third Party Advisory
https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org% Issue TrackingMailing List
https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org% Issue TrackingMailing List
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org% Issue TrackingMailing List
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org% Issue TrackingMailing List
https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org Issue TrackingMailing List
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org Issue TrackingMailing List

Track CVE-2010-0425 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2015-7450IBM products Java deserialization RCE via Commons CollectionsMultiple IBM analytics, business, IT infrastructure, and mobile/social products expose serialized-object interfaces that deserialize untrusted Java o…KEVEPSS 98%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed7.8CVE-2021-4034polkit pkexec argument handling flaw allows local root escalationpkexec, the setuid polkit utility for running commands as privileged users, mishandles the calling parameter count and ends up treating environment v…KEVEPSS 94%analysed7.8CVE-2019-0211Apache HTTP Server scoreboard use-after-free local privilege escalationApache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-p…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2010-0425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.