Vulnerability Name: CVE-2011-1883 (CCN-68309) Assigned: 2011-07-12 Published: 2011-07-12 Updated: 2020-09-28 Summary: Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability." CVSS v3 Severity: 9.3 Critical  (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Exploitability Metrics: Attack Vector (AV):  LocalAttack Complexity (AC):  LowPrivileges Required (PR):  NoneUser Interaction (UI):  NoneScope: Scope (S):  ChangedImpact Metrics: Confidentiality (C):  HighIntegrity (I):  HighAvailibility (A):  High
CVSS v2 Severity: 7.2 High  (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C 5.3 Medium  (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  LowAuthentication (Au):  NoneImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
6.9 Medium  (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C 5.1 Medium  (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  MediumAthentication (Au):  NoneImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
Vulnerability Type: CWE-399 Vulnerability Consequences: Gain Privileges References: Source: MITRECVE-2011-1883 73783 Microsoft Windows win32k.sys Driver Multiple Vulnerabilities 45186 http://support.avaya.com/css/P8/documents/100144947 Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2639417) Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2660465) Vulnerability in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2641653) Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578) Vulnerability in Silverlight Could Allow Remote Code Execution (2814124) Vulnerability in Windows Components Could Allow Remote Code Execution (2848295) Vulnerability in Windows Journal Could Allow Remote Code Execution (2975689) Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2555917) Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053) Vulnerability in Windows Kernel-Mode Drivers Could Allow Denial of Service (2617657) Microsoft Windows win32k.sys Driver Use After Free Unspecified Local Privilege Escalation (2011-1883) 48595 Microsoft Windows Kernel 'Win32k.sys' (CVE-2011-1883) Local Privilege Escalation Vulnerability 1025761 TA11-193A MS11-054 ms-win32sys-priv-escalation(68309) oval:org.mitre.oval:def:12721  Vulnerable Configuration: Configuration 1 :cpe:/o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_7:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x64:*  OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x86:*  OR cpe:/o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:*:*:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:-:sp2:itanium:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:*:sp1:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:*:sp2:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*  Configuration CCN 1 :cpe:/o:microsoft:windows:server_2003:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows:server_2003:sp2:itanium:*:*:*:*:*  OR cpe:/o:microsoft:windows:server_2003:sp2:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_xp::sp2:x64:*:professional:*:*:*  OR cpe:/o:microsoft:windows_vista:-:sp1:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows:xp:sp3:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:-:sp2:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_7:-:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*  Oval Definitions BACK 
microsoft  windows 2003 server * sp2    
microsoft  windows 7 -    
microsoft  windows 7 - sp1    
microsoft  windows 7 - sp1    
microsoft  windows server 2003 * sp2    
microsoft  windows server 2008 *    
microsoft  windows server 2008 *    
microsoft  windows server 2008 *    
microsoft  windows server 2008 * sp2    
microsoft  windows server 2008 * sp2    
microsoft  windows server 2008 - sp2    
microsoft  windows server 2008 r2    
microsoft  windows server 2008 r2    
microsoft  windows vista * sp1    
microsoft  windows vista * sp1    
microsoft  windows vista * sp2    
microsoft  windows vista * sp2    
microsoft  windows xp * sp3    
microsoft  windows xp - sp2    
microsoft  windows server_2003 sp2    
microsoft  windows server_2003 sp2    
microsoft  windows server_2003 sp2    
microsoft  windows xp  sp2    
microsoft  windows vista - sp1    
microsoft  windows server 2008 -    
microsoft  windows server 2008 -    
microsoft  windows server 2008 -    
microsoft  windows xp sp3    
microsoft  windows vista - sp2    
microsoft  windows vista - sp2    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 sp2    
microsoft  windows 7 - 
microsoft  windows server 2008 - r2    
microsoft  windows server 2008  r2    
microsoft  windows server 2008     
microsoft  windows 7 - sp1    
microsoft  windows server 2008 r2 sp1    
microsoft  windows server 2008 r2 sp1