Vulnerability Name: | CVE-2011-0045 (CCN-64926) | ||||||||
Assigned: | 2010-12-10 | ||||||||
Published: | 2011-02-08 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges via a crafted application, related to WmiTraceMessageVa, aka "Windows Kernel Integer Truncation Vulnerability." | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
5.4 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-0045 Source: OSVDB Type: UNKNOWN 70823 Source: SREASON Type: UNKNOWN 8110 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/css/P8/documents/100127248 Source: CCN Type: Microsoft Security Bulletin MS11-011 Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) Source: CCN Type: OSVDB ID: 70823 Microsoft Windows Kernel Trace Event (WmiTraceMessageVa) Handling Integer Truncation Local Privilege Escalation Source: BUGTRAQ Type: UNKNOWN 20110208 ZDI-11-064: Microsoft Windows WmiTraceMessageVa Local Kernel Vulnerability Source: BID Type: UNKNOWN 46136 Source: CCN Type: BID-46136 Microsoft Windows Kernel Integer Truncation Local Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1025046 Source: VUPEN Type: Vendor Advisory ADV-2011-0324 Source: MISC Type: UNKNOWN http://www.zerodayinitiative.com/advisories/ZDI-11-064 Source: MS Type: UNKNOWN MS11-011 Source: XF Type: UNKNOWN ms-win-kernel-privilege-escalation(64926) Source: XF Type: UNKNOWN ms-win-kernel-privilege-escalation(64926) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11996 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [03-01-2011] Source: CCN Type: ZDI-11-064 Microsoft Windows WmiTraceMessageVa Local Kernel Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |