Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-1243 | First vendor Publication | 2011-04-13 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Windows Messenger ActiveX control in msgsc.dll in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via unspecified vectors that "corrupt the system state," aka "Microsoft Windows Messenger ActiveX Control Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1243 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12524 | |||
Oval ID: | oval:org.mitre.oval:def:12524 | ||
Title: | Microsoft Windows Messenger ActiveX Control Vulnerability | ||
Description: | The Windows Messenger ActiveX control in msgsc.dll in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via unspecified vectors that "corrupt the system state," aka "Microsoft Windows Messenger ActiveX Control Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-1243 | Version: | 5 |
Platform(s): | Microsoft Windows XP | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 2 |
OpenVAS Exploits
Date | Description |
---|---|
2011-04-13 | Name : Microsoft IE Developer Tools WMITools and Windows Messenger ActiveX Control V... File : nvt/secpod_ms11-027.nasl |
2010-12-29 | Name : Microsoft WMI Administrative Tools ActiveX Control Remote Code Execution Vuln... File : nvt/gb_ms_wmi_admin_tools_activex_code_exec_vuln.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
71788 | Microsoft Windows Messenger ActiveX Unspecified Remote Code Execution |
Snort® IPS/IDS
Date | Description |
---|---|
2015-01-20 | Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access RuleID : 32842 - Revision : 4 - Type : BROWSER-PLUGINS |
2015-01-20 | Microsoft Windows Messenger ActiveX clsid access RuleID : 32841 - Revision : 3 - Type : BROWSER-PLUGINS |
2015-01-20 | Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access RuleID : 32840 - Revision : 4 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows WMI administrator tools object viewer ActiveX clsid access RuleID : 28351 - Revision : 7 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows WMI administrator tools object viewer ActiveX clsid access RuleID : 28350 - Revision : 7 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows WMI administrator tools object viewer ActiveX clsid access RuleID : 28349 - Revision : 7 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows Messenger ActiveX function call access RuleID : 26393 - Revision : 6 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access RuleID : 18672 - Revision : 8 - Type : BROWSER-IE |
2014-01-10 | Microsoft Windows Messenger ActiveX clsid access RuleID : 18668 - Revision : 15 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows WMI Administrator Tools Object Viewer ActiveX function call... RuleID : 18329 - Revision : 14 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows WMI Administrator Tools Object Viewer ActiveX function call... RuleID : 18242 - Revision : 15 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows WMI administrator tools object viewer ActiveX clsid access RuleID : 18241 - Revision : 17 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-04-13 | Name : The remote Windows host is missing an update that disables selected ActiveX c... File : smb_nt_ms11-027.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:05:28 |
|
2024-11-28 12:25:14 |
|
2021-05-04 12:14:13 |
|
2021-04-22 01:15:26 |
|
2020-05-23 00:28:06 |
|
2018-10-13 05:18:30 |
|
2017-09-19 09:24:20 |
|
2016-06-28 18:35:53 |
|
2016-04-26 20:39:08 |
|
2015-01-20 21:25:00 |
|
2014-02-17 11:01:18 |
|
2014-01-19 21:27:39 |
|
2013-05-10 22:57:10 |
|