Lucene search

K
cve[email protected]CVE-2011-1248
HistoryMay 13, 2011 - 5:05 p.m.

CVE-2011-1248

2011-05-1317:05:41
CWE-20
web.nvd.nist.gov
40
cve-2011-1248
microsoft windows
wins
server 2003
server 2008
remote code execution
memory corruption
denial of service
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.908 High

EPSS

Percentile

98.8%

WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka “WINS Service Failed Response Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_server_2003sp2
OR
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008sp2x32
OR
microsoftwindows_server_2008sp2x64
OR
microsoftwindows_server_2008Match-x64
OR
microsoftwindows_server_2008Matchr2x64

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.908 High

EPSS

Percentile

98.8%