Two more CVEs refer to this vulnerability as well: CVE-2010-3888 and CVE-2010-3889. However since the vendor has issued advisory with different CVE number, we will use the one issued by Microsoft.
The vulnerability has been exploited in тАЬprint-bombтАЭ attack as Stuxnet worm.
Vulnerability details
Advisory: SB2010091401 - Remote code execution in Print Spooler service in Microsoft Windows
Vulnerable component: Windows
CVE-ID: CVE-2010-2729
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:F/RL:O/RC:C
CWE-ID: CWE-284 - Improper Access Control
Description:
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to Windows Print Spooler service does not correctly restricts access permissions to create files for anonymous users. A remote attacker can send specially crafted RPC request to vulnerable service and upload malicious file to arbitrary location on the system.
This is a remote code execution vulnerability on Windows XP, since the guest account is enabled by default. On other operating systems this is a privilege escalation vulnerability, as only authenticated users have access to Print Spooler shares.
Successful exploitation of the vulnerability may result in remote code execution.
Note: this vulnerability is being actively exploited.
Known APT campaigns:
Iranian Nuclear Facilities breach
The breach was identified in summer 2010 by VirusBlokada antivirus company from Belarus, who was called to investigate computers in Iranian nuclear facilities.
Public Exploits:
External links:
https://technet.microsoft.com/en-us/library/security/ms10-061.aspx
https://securelist.com/analysis/kaspersky-security-bulletin/36345/kaspersky-security-bulletin-2010-s...
https://eatitorwearit.wordpress.com/tag/internal-attack/
https://svn.nmap.org/nmap-exp/sophron/nse-support/scripts/smb-vuln-ms10-061.nse
https://securelist.com/blog/incidents/29747/myrtus-and-guava-episode-ms10-061/ https://www.virusbulletin.com/conference/vb2010/abstracts/indepth-look-stuxnet
https://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=23897
http://seclists.org/metasploit/2010/q3/385
http://link.springer.com/chapter/10.1007%2F978-3-642-35211-9_81#page-1
https://securingtomorrow.mcafee.com/mcafee-labs/stuxnet-update/
http://www.enigmasoftware.com/w32printlove-removal/
http://researchcenter.paloaltonetworks.com/2010/10/stuxnet-scada-malware/