UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.
Conclusion & alert: CVE-2010-2075 is rated High Exploit Risk (79.7/100): CVSS High severity, with high exploitation likelihood (EPSS 87.20%, 99th percentile). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 16922 | exploit_db | edb | 2010-12-05 | Exploit-DB ↗ |
| 13853 | exploit_db | edb | 2010-06-13 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-08 | 87.34% | 87.20% | -0.14% |
| 2 | 2026-04-26 | 87.69% | 87.34% | -0.34% |
| 3 | 2026-04-24 | — | 87.69% | — |
Full EPSS history (33 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
high | CVE-2010-2075: 1 GLSA(s) (201006-21), 1 atom(s) (net-irc/unrealircd); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2010-2075 |
: Per: http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txt 'Official precompiled Windows binaries (SSL and non-ssl) are NOT affected. CVS is also not affected. 3.2.8 and any earlier versions are not affected. Any Unreal3.2.8.1.tar.gz downloaded BEFORE November 10 2009 should be safe, but you should really double-check, see next.'
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| unrealircd | unrealircd | 3.2.8.1 | cpe:2.3:a:unrealircd:unrealircd:3.2.8.1:*:*:*:*:*:*:* |