Vulnerability Name: | CVE-2011-1966 (CCN-68807) | ||||||||
Assigned: | 2011-08-09 | ||||||||
Published: | 2011-08-09 | ||||||||
Updated: | 2020-09-28 | ||||||||
Summary: | The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-1966 Source: CCN Type: SA45552 Microsoft Windows DNS Service Two Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS12-017 Vulnerability in DNS Server Could Allow Denial of Service (2647170) Source: CCN Type: Microsoft Security Bulletin MS15-127 Security Update for Microsoft Windows DNS to Address Remote Code Execution (3100465) Source: CCN Type: Microsoft Security Bulletin MS16-071 Security Update for Microsoft Windows DNS Server (3164065) Source: CCN Type: IBM Security Protection Alert Microsoft Windows DNS Server Could Allow Remote Code Execution Source: CCN Type: Microsoft Security Bulletin MS11-058 Vulnerabilities in DNS Server Could Allow Remote Code Execution (2562485) Source: CCN Type: BID-49012 Microsoft Windows DNS Server NAPTR Query Remote Heap Memory Corruption Vulnerability Source: CERT Type: US Government Resource TA11-221A Source: MS Type: UNKNOWN MS11-058 Source: XF Type: UNKNOWN ms-dns-code-execution(68807) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:12764 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |