Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2011-1984 | First vendor Publication | 2011-09-15 |
| Vendor | Cve | Last vendor Modification | 2012-02-13 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 7.2 | Attack Range | Local |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 3.9 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability." |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1984 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:12634 | |||
| Oval ID: | oval:org.mitre.oval:def:12634 | ||
| Title: | WINS Local Elevation of Privilege Vulnerability | ||
| Description: | WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2011-1984 |
Version: | 3 |
| Platform(s): | Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Os | 1 | |
| Os | 2 | |
| Os | 4 |
ExploitDB Exploits
| id | Description |
|---|---|
| 2011-09-13 | MS WINS ECommEndDlg Input Validation Error |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 75444 | Microsoft Windows WINS Loopback Interface Crafted Packet Local Privilege Esca... |
Internal Sources (Detail)
| Source | Url |
|---|---|
| CERT | http://www.us-cert.gov/cas/techalerts/TA11-256A.html |
| MS | http://technet.microsoft.com/en-us/security/bulletin/MS11-070 |
| SREASON | http://securityreason.com/securityalert/8378 |
Alert History
| Date | Informations |
|---|---|
| 2013-05-10 23:00:56 |
|
| 2013-05-01 17:22:40 |
|
| 2013-05-01 13:28:08 |
|
| 2013-05-01 09:22:49 |
|
| 2013-05-01 05:38:33 |
|

CVE-2011-1984
(Critical)
(High)







