Lucene search

K
cveMicrosoftCVE-2011-1868
HistoryJun 16, 2011 - 8:55 p.m.

CVE-2011-1868

2011-06-1620:55:02
CWE-119
microsoft
web.nvd.nist.gov
35
cve-2011-1868
dfs
memory corruption
vulnerability
windows xp
server 2003
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.202

Percentile

96.4%

The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka β€œDFS Memory Corruption Vulnerability.”

Affected configurations

Nvd
Node
microsoftwindows_2003_serversp2
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xpsp3
OR
microsoftwindows_xpMatch-sp2x64
VendorProductVersionCPE
microsoftwindows_2003_servercpe:/o:microsoft:windows_2003_server::sp2::
microsoftwindows_xp-cpe:/o:microsoft:windows_xp:-:sp2::
microsoftwindows_server_2003cpe:/o:microsoft:windows_server_2003::sp2::
microsoftwindows_xpcpe:/o:microsoft:windows_xp::sp3::

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.202

Percentile

96.4%