Lucene search

K
cveMicrosoftCVE-2011-1229
HistoryApr 13, 2011 - 8:26 p.m.

CVE-2011-1229

2011-04-1320:26:25
CWE-476
microsoft
web.nvd.nist.gov
46
2
cve-2011-1229
win32k
windows xp
windows server
windows vista
windows 7
nvd
null pointer
privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.8%

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other “Vulnerability Type 2” CVEs listed in MS11-034, aka “Win32k Null Pointer De-reference Vulnerability.”

Affected configurations

Nvd
Node
microsoftwindows_2003_serverMatch-sp2
OR
microsoftwindows_7Match-
OR
microsoftwindows_7Match-sp1
OR
microsoftwindows_server_2003Match-sp2
OR
microsoftwindows_server_2008Match-
OR
microsoftwindows_server_2008Match-sp2
OR
microsoftwindows_server_2008Matchr2itanium
OR
microsoftwindows_server_2008Matchr2x64
OR
microsoftwindows_server_2008Matchr2sp1itanium
OR
microsoftwindows_server_2008Matchr2sp1x64
OR
microsoftwindows_vistaMatch-sp1
OR
microsoftwindows_vistaMatch-sp1x64
OR
microsoftwindows_vistaMatch-sp2
OR
microsoftwindows_vistaMatch-sp2x64
OR
microsoftwindows_xpMatch-sp2x64
OR
microsoftwindows_xpMatch-sp3
Node
avayaagent_access
OR
avayaaura_conferencing_standard_editionMatch6.0.0
OR
avayabasic_call_management_system_reporting_desktop
OR
avayacall_management_server_supervisor
OR
avayacallpilotRange4.0.x5.0.x
OR
avayacallvisor_asai_lan
OR
avayacommunication_server_1000_telephony_managerRange3.0.04.0.0
OR
avayacomputer_telephony
OR
avayacontact_center_express
OR
avayacustomer_interaction_express
OR
avayaenterprise_manager
OR
avayaintegrated_management
OR
avayainteraction_center
OR
avayaip_agent
OR
avayaip_softphone
OR
avayameeting_exchangeRange5.0.05.2.0
OR
avayamessaging_application_serverRange4.0.x5.2.x
OR
avayanetwork_reporting
OR
avayaoctelaccess_server
OR
avayaocteldesigner
OR
avayaoperational_analyst
OR
avayaoutbound_contact_management
OR
avayaspeech_access
OR
avayaunified_communication_center
OR
avayaunified_messenger
OR
avayavisual_messenger
OR
avayavisual_vector_client
OR
avayavpnmanager_console
OR
avayaweb_messenger
VendorProductVersionCPE
microsoftwindows_2003_server-cpe:2.3:o:microsoft:windows_2003_server:-:sp2:*:*:*:*:*:*
microsoftwindows_7-cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
microsoftwindows_7-cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
microsoftwindows_server_2003-cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*
microsoftwindows_server_2008-cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*
microsoftwindows_server_2008-cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
microsoftwindows_server_2008r2cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:itanium:*
microsoftwindows_server_2008r2cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:*
microsoftwindows_server_2008r2cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
microsoftwindows_server_2008r2cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
Rows per page:
1-10 of 451

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.8%