Vulnerability record · CVE-2010-3973 · published 23 December 2010
CVE-2010-3973: Microsoft WMI Administrative Tools WMITools ActiveX control remote code execution
Microsoft · Wmi Administrative Tools
The WMITools ActiveX control (WBEMSingleView.ocx 1.50.1131.0) in Microsoft WMI Administrative Tools 1.1 and earlier on Windows XP SP2/SP3 mishandles a crafted argument to the AddContextRef method, likely an untrusted pointer dereference. A remote attacker can trigger memory corruption that leads to arbitrary code execution in the context of the user who loads the control. The flaw matters because the control is reachable from a web page and public exploit code exists.
Description
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with public exploit code and very high EPSS, but exploitation requires user interaction and the affected product is a legacy, non-default administrative tool.
What it is
The WMITools ActiveX control (WBEMSingleView.ocx 1.50.1131.0) in Microsoft WMI Administrative Tools 1.1 and earlier on Windows XP SP2/SP3 mishandles a crafted argument to the AddContextRef method, likely an untrusted pointer dereference. A remote attacker can trigger memory corruption that leads to arbitrary code execution in the context of the user who loads the control. The flaw matters because the control is reachable from a web page and public exploit code exists.
Impact
An attacker who successfully exploits the control gains arbitrary code execution with the privileges of the logged-on user. That allows installation of malware, data theft, or further compromise of the host.
Attack surface
Reached over the network by luring a user to a malicious or compromised web page that instantiates the WMITools ActiveX control; no authentication is required, but user interaction (loading the page in a browser that permits the control) is needed, consistent with the AV:N/AC:M/Au:N vector.
Exploitation
Public exploit code is referenced (Exploit-DB 15809, SecurityFocus BID 45546, Wooyun 1006), and EPSS is 0.71735 (99.4th percentile), indicating high predicted exploitation activity; the CVE is not listed in CISA KEV.
What to do
- Apply Microsoft security update MS11-027, which addresses the WMITools ActiveX control vulnerability.
- If the update cannot be applied immediately, disable or kill-bit the WBEMSingleView.ocx ActiveX control in Internet Explorer.
- Remove Microsoft WMI Administrative Tools 1.1 or earlier from systems that do not require it.
- Restrict browsing to trusted sites and enforce ActiveX controls to prompt or block where feasible.
Detection
- Monitor for processes loading WBEMSingleView.ocx, especially from browser processes such as iexplore.exe.
- Hunt for unexpected child processes spawned by browsers or by rundll32.exe/regsvr32.exe loading the control.
- Review proxy and web logs for pages that reference the WMITools ActiveX CLSID or known exploit hosts.
- Check endpoint telemetry for crashes or memory corruption events in WBEMSingleView.ocx.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3973 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3973), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.