Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-1265 | First vendor Publication | 2011-07-13 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 8.8 | ||
Base Score | 8.8 | Environmental Score | 8.8 |
impact SubScore | 5.9 | Temporal Score | 8.8 |
Exploitabality Sub Score | 2.8 | ||
Attack Vector | Adjacent | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:A/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 8.3 | Attack Range | Adjacent network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 6.5 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1265 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12094 | |||
Oval ID: | oval:org.mitre.oval:def:12094 | ||
Title: | Bluetooth Stack Vulnerability | ||
Description: | The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-1265 | Version: | 10 |
Platform(s): | Microsoft Windows Vista Microsoft Windows 7 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Os | 1 | |
Os | 2 |
OpenVAS Exploits
Date | Description |
---|---|
2011-07-13 | Name : Microsoft Bluetooth Stack Remote Code Execution Vulnerability (2566220) File : nvt/secpod_ms11-053.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
73799 | Microsoft Windows Bluetooth Driver Object Handling Remote Code Execution |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2011-07-14 | IAVM : 2011-A-0100 - Microsoft Windows Bluetooth Stack Remote Code Execution Vulnerability Severity : Category I - VMSKEY : V0029384 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-06-07 | Microsoft Windows NtUserMessageCall implementation exploitation attempt RuleID : 30940 - Revision : 5 - Type : FILE-EXECUTABLE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-07-12 | Name : Arbitrary code can be executed on the remote host through Bluetooth. File : smb_nt_ms11-053.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:04:44 |
|
2024-11-28 12:25:14 |
|
2021-05-04 12:15:19 |
|
2021-04-22 01:16:52 |
|
2020-05-23 00:28:06 |
|
2019-09-27 21:19:48 |
|
2019-05-09 12:03:46 |
|
2018-10-31 00:20:13 |
|
2018-10-13 05:18:31 |
|
2017-09-19 09:24:20 |
|
2016-08-05 12:02:59 |
|
2014-09-08 21:23:09 |
|
2014-09-04 21:23:24 |
|
2014-02-17 11:01:21 |
|
2013-11-11 12:39:17 |
|
2013-05-10 22:57:15 |
|