Vulnerability record · CVE-2010-3964 · published 16 December 2010
CVE-2010-3964: SharePoint Server 2007 Document Conversions Service unrestricted file upload RCE
Microsoft · Sharepoint Server
The Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2 fails to restrict file uploads, allowing a crafted SOAP request to TCP port 8082 to execute arbitrary code. The flaw only applies when the Document Conversions Load Balancer Service is enabled, so exposure depends on that configuration.
Description
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with a very high EPSS score, though the flaw requires the Load Balancer Service to be enabled and the product is legacy.
What it is
The Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2 fails to restrict file uploads, allowing a crafted SOAP request to TCP port 8082 to execute arbitrary code. The flaw only applies when the Document Conversions Load Balancer Service is enabled, so exposure depends on that configuration.
Impact
A remote attacker can run arbitrary code on the SharePoint server, gaining the privileges of the affected service and potentially full control of the host.
Attack surface
Reached over the network via a crafted SOAP request to TCP port 8082; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.942, 99.8th percentile), suggesting elevated likelihood of exploitation activity; reference tags are vendor and government advisories only, with no public exploit tag.
What to do
- Apply Microsoft security bulletin MS10-104 for SharePoint Server 2007 SP2.
- Disable the Document Conversions Load Balancer Service where it is not required, since the flaw only applies when it is enabled.
- Restrict network access to TCP port 8082 to trusted hosts only.
- Monitor and audit the Document Conversions Launcher Service for unexpected SOAP traffic.
- Upgrade to a supported SharePoint version, as 2007 SP2 is long out of support.
Detection
- Inspect network traffic and logs for malformed or unexpected SOAP requests to TCP port 8082.
- Alert on Document Conversions Launcher Service crashes or restarts.
- Monitor for new or modified files or processes spawned by the SharePoint service account.
- Review SharePoint and host logs for anomalous activity following Document Conversions requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3964 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3964), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.