ID

VAR-201003-0493


CVE

CVE-2010-1184


TITLE

Microsoft A vulnerability that allows arbitrary commands to be inserted into a wireless keyboard

Trust: 0.8

sources: JVNDB: JVNDB-2010-004635

DESCRIPTION

The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2. There is a vulnerability in the encryption algorithm of the Microsoft wireless keyboard

Trust: 1.71

sources: NVD: CVE-2010-1184 // JVNDB: JVNDB-2010-004635 // VULHUB: VHN-43789

AFFECTED PRODUCTS

vendor:microsoftmodel:27mhz wireless keyboardscope: - version: -

Trust: 1.4

vendor:microsoftmodel:27mhz wireless keyboardscope:eqversion:*

Trust: 1.0

sources: JVNDB: JVNDB-2010-004635 // CNNVD: CNNVD-201003-446 // NVD: CVE-2010-1184

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2010-1184
value: HIGH

Trust: 1.0

NVD: CVE-2010-1184
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201003-446
value: HIGH

Trust: 0.6

VULHUB: VHN-43789
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2010-1184
severity: HIGH
baseScore: 7.6
vectorString: AV:N/AC:H/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-43789
severity: HIGH
baseScore: 7.6
vectorString: AV:N/AC:H/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-43789 // JVNDB: JVNDB-2010-004635 // CNNVD: CNNVD-201003-446 // NVD: CVE-2010-1184

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.9

sources: VULHUB: VHN-43789 // JVNDB: JVNDB-2010-004635 // NVD: CVE-2010-1184

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201003-446

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201003-446

CONFIGURATIONS

sources: JVNDB: JVNDB-2010-004635

PATCH

title:Microsoft Hardwareurl:http://www.microsoft.com/hardware/en-us

Trust: 0.8

sources: JVNDB: JVNDB-2010-004635

EXTERNAL IDS

db:NVDid:CVE-2010-1184

Trust: 2.5

db:JVNDBid:JVNDB-2010-004635

Trust: 0.8

db:CNNVDid:CNNVD-201003-446

Trust: 0.7

db:VULHUBid:VHN-43789

Trust: 0.1

sources: VULHUB: VHN-43789 // JVNDB: JVNDB-2010-004635 // CNNVD: CNNVD-201003-446 // NVD: CVE-2010-1184

REFERENCES

url:http://www.remote-exploit.org/?p=437

Trust: 1.7

url:http://www.theregister.co.uk/2010/03/26/open_source_wireless_sniffer/

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/57978

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2010-1184

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2010-1184

Trust: 0.8

sources: VULHUB: VHN-43789 // JVNDB: JVNDB-2010-004635 // CNNVD: CNNVD-201003-446 // NVD: CVE-2010-1184

SOURCES

db:VULHUBid:VHN-43789
db:JVNDBid:JVNDB-2010-004635
db:CNNVDid:CNNVD-201003-446
db:NVDid:CVE-2010-1184

LAST UPDATE DATE

2025-04-11T23:16:54.515000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-43789date:2017-08-17T00:00:00
db:JVNDBid:JVNDB-2010-004635date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-201003-446date:2010-03-30T00:00:00
db:NVDid:CVE-2010-1184date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-43789date:2010-03-29T00:00:00
db:JVNDBid:JVNDB-2010-004635date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-201003-446date:2010-03-29T00:00:00
db:NVDid:CVE-2010-1184date:2010-03-29T22:30:00.377