← Vulnerability feed

Vulnerability record · CVE-2010-2075 · published 15 June 2010

CVE-2010-2075: UnrealIRCd backdoor in DEBUG3_DOLOG_SYSTEM macro allows remote command execution

Unrealircd · Unrealircd

UnrealIRCd 3.2.8.1 distributed from certain mirror sites between November 2009 and June 2010 contained an externally introduced Trojan Horse modification in the DEBUG3_DOLOG_SYSTEM macro. The tampered code lets a remote attacker execute arbitrary commands on the IRC server. Because the malicious code was shipped in the official-looking distribution, operators who downloaded from the affected mirrors ran a backdoored daemon without knowing it.

7.5 CVSS 2.0 High EPSS 84% · top 0.3% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote command execution with public exploit code and very high EPSS, though the affected distribution window is old and KEV does not list it.

What it is

UnrealIRCd 3.2.8.1 distributed from certain mirror sites between November 2009 and June 2010 contained an externally introduced Trojan Horse modification in the DEBUG3_DOLOG_SYSTEM macro. The tampered code lets a remote attacker execute arbitrary commands on the IRC server. Because the malicious code was shipped in the official-looking distribution, operators who downloaded from the affected mirrors ran a backdoored daemon without knowing it.

Impact

An attacker gains remote command execution on the IRC server, typically with the privileges of the UnrealIRCd process. That allows full compromise of the host, including data theft, further lateral movement, or use of the server as a botnet or DDoS relay.

Attack surface

Reachable over the network via the IRC service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described in the record.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.835 probability, 99.7th percentile) and references include an Exploit-DB entry and a SecurityFocus BID tagged Exploit, indicating public exploit code exists.

What to do

  • Replace any UnrealIRCd 3.2.8.1 binary obtained from mirror sites between November 2009 and June 2010 with a clean build from the official UnrealIRCd source or vendor.
  • Verify the integrity of the installed binary against the vendor advisory and known-good hashes before trusting the host.
  • If a backdoored build was running, treat the host as compromised: rebuild it and rotate all credentials and keys that were present.
  • Restrict IRC service exposure to trusted networks and monitor for unexpected outbound connections from the IRC host.

Detection

  • Search hosts for UnrealIRCd 3.2.8.1 binaries and compare hashes against the official release.
  • Monitor IRC server process for unexpected child processes or shell execution, which would indicate the backdoor being triggered.
  • Review network logs for anomalous outbound connections originating from the IRC server to unknown destinations.
  • Check file timestamps and package provenance for UnrealIRCd installs from the affected mirror window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-2075 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2016-7144Unrealircd improper authentication vulnerabilityThe m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate finge…EPSS 1.3%7.5CVE-2023-50784Unrealircd classic buffer overflow vulnerabilityA buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker to crash the server by sendi…EPSS 1.9%6.8CVE-2009-4893Unrealircd memory buffer overflow vulnerabilityBuffer overflow in UnrealIRCd 3.2beta11 through 3.2.8, when allow::options::noident is enabled, allows remote attackers to cause a denial of service …EPSS 2.5%5.5CVE-2017-13649Unrealircd vulnerabilityUnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary pro…EPSS 0.28%5.0CVE-2013-7384Unrealircd vulnerabilityUnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, …EPSS 2.4%5.0CVE-2013-6413Unrealircd vulnerabilityUse-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vector…EPSS 2.4%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2010-2075), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.