CVE-2010-2075Active Exploitation(unrealircd / unrealircd)

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for unrealircd unrealircd systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unrealircd

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
unrealircd

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-26: 1Active Exploitation · 2026-02-26: 1Technical Details · 2026-02-26: 102-26
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Jenkox.33@Jenkox33_Shadow
    Active Exploitation

    Additional findings related to the entire 1999-current date chain. Part 1 CVEs were used as attack vectors targeting mirc 2002 entropyhooks.dll mag_hook.dll narhook.dll May 2003 stunrun/stuntour October 2003 CVE-2003-1336 (mIRC buffer overflow) CVE-2010-2075 (Unreal 3.2.8.1) This shows consistent unauthorized access by using CVEs as an attack method and falls in line with the already documented attack method The previous attack methodology shows @Microsoft abusing windows defender policies and registry information

    Post summary

    The text reports that CVE-2003-1336 and CVE-2010-2075 were actively exploited to gain unauthorized access, with evidence of consistent use as attack vectors, but no PoC or patch details are provided.

    1000035
    36 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appunrealircdunrealircd3.2.8.1--

Explore more