CVE-2011-1889
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-03-03Remediation due 2022-03-24
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
9.8
CVSS
49.0%
EPSS (exploit prob.)
99th
EPSS percentile
2011-06-16
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | forefront_threat_management_gateway | 2010 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/44857
- http://www.securityfocus.com/bid/48181
- http://www.securitytracker.com/id?1025637
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67736
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12642
- http://secunia.com/advisories/44857
- http://www.securityfocus.com/bid/48181
- http://www.securitytracker.com/id?1025637
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67736
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12642
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-1889
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-1889