CVE-2011-1966
high · 10The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."
10
CVSS
55.2%
EPSS (exploit prob.)
99th
EPSS percentile
2011-08-10
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | r2 |
Check a specific version with /api/v1/cve/match.
References
- http://www.us-cert.gov/cas/techalerts/TA11-221A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-058
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12764
- http://www.us-cert.gov/cas/techalerts/TA11-221A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-058
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12764
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-1966