CVE-2011-1889
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Forefront TMG Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 48% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-119
מוצרים מושפעים
microsoft: forefront threat management gateway
קישורים
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-… PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-… PatchVendor Advisory
- http://secunia.com/advisories/44857 Broken Link
- http://www.securityfocus.com/bid/48181 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1025637 Broken LinkThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67736 Third Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link
- http://secunia.com/advisories/44857 Broken Link
- http://www.securityfocus.com/bid/48181 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1025637 Broken LinkThird Party AdvisoryVDB Entry