← Vulnerability feed

Vulnerability record · CVE-2010-3964 · published 16 December 2010

CVE-2010-3964: SharePoint Server 2007 Document Conversions Service unrestricted file upload RCE

Microsoft · Sharepoint Server

The Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2 fails to restrict file uploads, allowing a crafted SOAP request to TCP port 8082 to execute arbitrary code. The flaw only applies when the Document Conversions Load Balancer Service is enabled, so exposure depends on that configuration.

7.5 CVSS 2.0 High EPSS 94% · top 0.2%
7.5CVSS 2.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with a very high EPSS score, though the flaw requires the Load Balancer Service to be enabled and the product is legacy.

What it is

The Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2 fails to restrict file uploads, allowing a crafted SOAP request to TCP port 8082 to execute arbitrary code. The flaw only applies when the Document Conversions Load Balancer Service is enabled, so exposure depends on that configuration.

Impact

A remote attacker can run arbitrary code on the SharePoint server, gaining the privileges of the affected service and potentially full control of the host.

Attack surface

Reached over the network via a crafted SOAP request to TCP port 8082; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.942, 99.8th percentile), suggesting elevated likelihood of exploitation activity; reference tags are vendor and government advisories only, with no public exploit tag.

What to do

  • Apply Microsoft security bulletin MS10-104 for SharePoint Server 2007 SP2.
  • Disable the Document Conversions Load Balancer Service where it is not required, since the flaw only applies when it is enabled.
  • Restrict network access to TCP port 8082 to trusted hosts only.
  • Monitor and audit the Document Conversions Launcher Service for unexpected SOAP traffic.
  • Upgrade to a supported SharePoint version, as 2007 SP2 is long out of support.

Detection

  • Inspect network traffic and logs for malformed or unexpected SOAP requests to TCP port 8082.
  • Alert on Document Conversions Launcher Service crashes or restarts.
  • Monitor for new or modified files or processes spawned by the SharePoint service account.
  • Review SharePoint and host logs for anomalous activity following Document Conversions requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-3964 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-20963Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 30%analysed9.8CVE-2025-53770Microsoft SharePoint Server deserialization RCE under active exploitationOn-premises Microsoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker run code on the server. Microsoft st…KEVEPSS 100%analysed9.8CVE-2023-29357Microsoft SharePoint Server elevation of privilege via authentication bypassCVE-2023-29357 is a critical elevation of privilege flaw in Microsoft SharePoint Server. The CVSS vector shows it is network reachable with no privil…KEVEPSS 100%analysed9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed9.1CVE-2026-55040Microsoft SharePoint weak authentication allows network security feature bypassMicrosoft SharePoint Server contains a weak authentication flaw (CWE-1390) that lets an unauthorized attacker bypass a security feature over the netw…KEVEPSS 18%analysed

Source: NIST National Vulnerability Database (record CVE-2010-3964), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.