Vulnerability Name: | CVE-2011-1248 (CCN-67100) | ||||||||
Assigned: | 2011-05-10 | ||||||||
Published: | 2011-05-10 | ||||||||
Updated: | 2020-09-28 | ||||||||
Summary: | WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.3 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
7.8 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-1248 Source: CCN Type: SA44538 Microsoft Windows WINS Service Failed Response Data Reuse Vulnerability Source: CCN Type: Microsoft Security Bulletin MS11-035 Vulnerability in WINS Could Allow Remote Code Execution (2524426) Source: CCN Type: Microsoft Security Bulletin MS11-070 Vulnerability in WINS Could Allow Elevation of Privilege (2571621) Source: CCN Type: BID-47730 Microsoft Windows Internet Name Service (WINS) Failed Response Remote Code Execution Vulnerability Source: MS Type: UNKNOWN MS11-035 Source: XF Type: UNKNOWN ms-win-wins-code-exec(67100) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:12724 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [09-13-2011] Source: CCN Type: ZDI-11-167 Microsoft WINS Service Failed Response Memory Corruption Remote Code Execution Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |