CVE-2010-0425
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request proc...
Affects 6 products across 5 vendors.
A vulnerability in the mod_isapi module of the Apache HTTP Server allows remote attackers to execute arbitrary code due to improper handling of request processing completion before unloading an ISAPI .dll module.
BSID: BS-2010-GLOBAL-171958-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2010-0425?
What is the CVSS score for CVE-2010-0425?
Is CVE-2010-0425 actively exploited?
How do I remediate CVE-2010-0425?
What systems are affected by CVE-2010-0425?
| CVE ID | CVE-2010-0425 |
|---|---|
| BSID | BS-2010-GLOBAL-171958-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2010-03-05 |
| Last Modified | 2025-07-24 |
| ICS Relevance | 0% |
| Source | NVD |
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
Source: NIST NVD / MITRE CVE Database
The attack involves sending a crafted request or a reset packet to the server, which can lead to the execution of arbitrary code if the ISAPI .dll module is not properly managed during unloading.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Apache | Http Server | — |
| Broadcom | Vmware Ace Management Server | — |
| Ibm | Websphere Application Server | — |
| Ibm | Http Server | — |
| Microsoft | Windows | — |
| Oracle | Http Server | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →