Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."
Use CWE-94, Microsoft vendor hub and Internet Information Server product page to widen CVE-2010-1256 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2008-0075, CVE-2009-3023 and CVE-2007-0087 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.