Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-0657 | First vendor Publication | 2011-04-13 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0657 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:11902 | |||
Oval ID: | oval:org.mitre.oval:def:11902 | ||
Title: | DNS Query Vulnerability | ||
Description: | DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-0657 | Version: | 5 |
Platform(s): | Microsoft Windows XP Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 7 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-03-06 | Name : Microsoft SMB Transaction Parsing Remote Code Execution Vulnerability File : nvt/secpod_ms11-020_remote.nasl |
2011-04-13 | Name : Microsoft DNS Resolution Remote Code Execution Vulnerability (2509553) File : nvt/secpod_ms11-030.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
71780 | Microsoft Windows DNS Client Service LLMNR Query Processing Remote Code Execu... Microsoft Windows contains a flaw related to the DNSAPI.dll component in the DNS client failing to properly process DNS queries. This may allow a remote attacker to use a crafted LLMNR broadcast query to TCP/UDP port 5355, or a crafted application to execute arbitrary code. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2011-04-14 | IAVM : 2011-A-0039 - Microsoft DNS Resolution Remote Code Execution Vulnerability Severity : Category I - VMSKEY : V0026514 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows LLMNR invalid reverse name lookup stack corruption attempt RuleID : 18655 - Revision : 12 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-04-21 | Name : Arbitrary code can be executed on the remote host through the installed Windo... File : llmnr-ms11-030.nasl - Type : ACT_GATHER_INFO |
2011-04-13 | Name : Arbitrary code can be executed on the remote host through the installed Windo... File : smb_nt_ms11-030.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:05:28 |
|
2024-11-28 12:24:47 |
|
2024-10-18 00:28:11 |
|
2024-08-02 12:15:51 |
|
2024-08-02 01:04:22 |
|
2024-02-02 01:15:23 |
|
2024-02-01 12:04:17 |
|
2023-12-07 21:28:03 |
|
2023-09-05 12:14:23 |
|
2023-09-05 01:04:08 |
|
2023-09-02 12:14:26 |
|
2023-09-02 01:04:12 |
|
2023-08-12 12:17:22 |
|
2023-08-12 01:04:12 |
|
2023-08-11 12:14:31 |
|
2023-08-11 01:04:20 |
|
2023-08-06 12:13:57 |
|
2023-08-06 01:04:13 |
|
2023-08-04 12:14:02 |
|
2023-08-04 01:04:14 |
|
2023-07-14 12:14:00 |
|
2023-07-14 01:04:12 |
|
2023-03-29 01:15:56 |
|
2023-03-28 12:04:18 |
|
2022-10-11 12:12:29 |
|
2022-10-11 01:03:58 |
|
2021-05-04 12:13:58 |
|
2021-04-22 01:15:08 |
|
2020-09-28 17:22:42 |
|
2020-05-23 00:27:46 |
|
2019-05-09 12:03:40 |
|
2019-02-26 17:19:34 |
|
2018-10-31 00:20:11 |
|
2018-10-13 00:23:03 |
|
2018-09-20 12:08:46 |
|
2017-09-19 09:24:13 |
|
2016-09-30 01:02:48 |
|
2016-08-31 12:02:32 |
|
2016-08-05 12:02:53 |
|
2016-06-28 18:32:47 |
|
2016-04-26 20:32:27 |
|
2014-02-17 11:00:22 |
|
2014-01-19 21:27:35 |
|
2013-11-11 12:39:11 |
|
2013-05-10 22:54:23 |
|