CVE-2010-3964
Status: ModifiedHigh (7.5)—💥 Exploit
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 94%
- Percentile among all scored CVEs: 100
- Score date: 10/3/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Metasploit module (reliable, widely available exploit) · MS10-104 Microsoft Office SharePoint Server 2007 Remote Code Execution
- Published on Exploit-DB · Microsoft Office SharePoint Server 2007 - Remote Code Execution (MS10-104) (Metasploit) (7/31/2012)
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://osvdb.org/69817
- http://secunia.com/advisories/42631
- http://www.securityfocus.com/bid/45264
- http://www.securitytracker.com/id?1024886
- http://www.us-cert.gov/cas/techalerts/TA10-348A.html
- http://www.vupen.com/english/advisories/2010/3226
- http://www.zerodayinitiative.com/advisories/ZDI-10-287/
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-104
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11737
- http://osvdb.org/69817
- http://secunia.com/advisories/42631
- http://www.securityfocus.com/bid/45264
- http://www.securitytracker.com/id?1024886
- http://www.us-cert.gov/cas/techalerts/TA10-348A.html
- http://www.vupen.com/english/advisories/2010/3226
- http://www.zerodayinitiative.com/advisories/ZDI-10-287/
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-104
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11737
Raw JSON (NVD)
Show
{
"id": "CVE-2010-3964",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-12-16T19:33:03.367",
"references": [
{
"url": "http://osvdb.org/69817",
"source": "secure@microsoft.com"
},
{
"url": "http://secunia.com/advisories/42631",
"tags": [
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/45264",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securitytracker.com/id?1024886",
"source": "secure@microsoft.com"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA10-348A.html",
"tags": [
"US Government Resource"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3226",
"tags": [
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-10-287/",
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-104",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11737",
"source": "secure@microsoft.com"
},
{
"url": "http://osvdb.org/69817",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42631",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/45264",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1024886",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA10-348A.html",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3226",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-10-287/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-104",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11737",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka \"Malformed Request Code Execution Vulnerability.\""
},
{
"lang": "es",
"value": "Vulnerabilidad de subida de archivos sin restricciones en el Document Conversions Launcher Service en Microsoft Office SharePoint Server 2007 SP2, cuando Document Conversions Load Balancer Service está habilitado, permite a los atacantes remotos ejecutar código arbitrario mediante una solicitud SOAP diseñada al puerto TCP 8082, también se conoce como \"Malformed Request Code Execution Vulnerability.\""
}
],
"lastModified": "2026-06-16T23:23:54.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2007:sp2:x32:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "586E6C37-346C-40BA-AC89-2CEB8C44E190"
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2007:sp2:x64:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48EB5C93-55BF-4608-A9DC-EDD8DE15EE44"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "Additional information from Microsoft can be found here:\r\n\r\nhttp://blogs.technet.com/b/srd/archive/2010/12/14/ms10-104-sharepoint-2007-vulnerability.aspx\r\n\r\nPer: http://cwe.mitre.org/data/definitions/434.html\r\n\r\n'CWE-434: Unrestricted Upload of File with Dangerous Type'",
"sourceIdentifier": "secure@microsoft.com"
}