| Vulnerability Name: | CVE-2011-1868 (CCN-67726) | ||||||||
| Assigned: | 2011-06-14 | ||||||||
| Published: | 2011-06-14 | ||||||||
| Updated: | 2019-02-26 | ||||||||
| Summary: | The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka "DFS Memory Corruption Vulnerability." | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-119 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2011-1868 Source: CCN Type: SA44894 Microsoft Windows Distributed File System Two Vulnerabilities Source: SECUNIA Type: UNKNOWN 44894 Source: CCN Type: IBM Security Protection Alert Microsoft Windows Distributed File System Could Allow Remote Code Execution Source: CCN Type: Microsoft Security Bulletin MS11-042 Vulnerabilities in Distributed File System Could Allow Remote Code Execution (2535512) Source: BID Type: UNKNOWN 48180 Source: CCN Type: BID-48180 Microsoft Windows Distributed File System Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1025639 Source: MS Type: UNKNOWN MS11-042 Source: XF Type: UNKNOWN ms-win-dfs-code-exec(67726) Source: XF Type: UNKNOWN ms-win-dfs-code-exec(67726) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11758 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||