CVE-2011-0666
published 2011-04-13CVE-2011-0666: Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2…
PriorityP432high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
1.43%
70.1th percentile
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6h85-h7jp-9g6v: Use-after-free vulnerability in win32k
ghsa_unreviewed·2022-05-13
CVE-2011-0666 [HIGH] GHSA-6h85-h7jp-9g6v: Use-after-free vulnerability in win32k
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
Red Hat
OpenIPMI: IPMI event daemon creates PID file with world writeable permissions
vendor_redhat·2011-12-13·CVSS 3.6
CVE-2011-4339 [LOW] OpenIPMI: IPMI event daemon creates PID file with world writeable permissions
OpenIPMI: IPMI event daemon creates PID file with world writeable permissions
ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file.
Package: OpenIPMI (Red Hat Enterprise Linux 4) - Not affected
Red Hat
openswan: World writable pid and lock files
vendor_redhat·2011-05-11·CVSS 3.6
CVE-2011-2147 [LOW] openswan: World writable pid and lock files
openswan: World writable pid and lock files
Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec starter, and (2) /var/lock/subsys/ipsec, which allows local users to kill arbitrary processes by writing a PID to a file, or possibly bypass disk quotas by writing arbitrary data to a file, as demonstrated by files with 0666 permissions, a different vulnerability than CVE-2011-1784.
Statement: Not vulnerable. This issue did not affect the versions of openswan as shipped with Red Hat Enterprise Linux 5 or 6.
Package: openswan (Red Hat Enterprise Linux 5) - Not affected
Package: openswan (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4339 OpenIPMI: IPMI event daemon creates PID file with world writeable permissions
bugzilla·2011-10-03·CVSS 3.6
CVE-2011-4339 [LOW] CVE-2011-4339 OpenIPMI: IPMI event daemon creates PID file with world writeable permissions
CVE-2011-4339 OpenIPMI: IPMI event daemon creates PID file with world writeable permissions
A insecure file permissions flaw was found in the way IPMI event daemon of the OpenIPMI (Intelligent Platform Management Interface) library and tools created its PID file (it was created with 0666 permissions). A local user could use this flaw to kill arbitrary running process during ipmievd service shutdown.
Discussion:
This issue did NOT affect the version of the OpenIPMI package, as shipped with Red Hat Enterprise Linux 4.
--
This issue did NOT affect the version of the OpenIPMI package, as shipped with Red Hat Enterprise Linux 5 in the default configuration. Though custom configurations of the ipmievd daemon (those using /var/run/ipmievd.pid as a PID file) are affected by this issue too.
-
Bugzilla
CVE-2011-2147 openswan: World writable pid and lock files
bugzilla·2011-05-30·CVSS 3.6
CVE-2011-2147 [LOW] CVE-2011-2147 openswan: World writable pid and lock files
CVE-2011-2147 openswan: World writable pid and lock files
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-2147 to
the following vulnerability:
Openswan 2.2.x does not properly restrict permissions for (1) /var/run/
starter.pid, related to starter.c in the IPsec starter, and (2) /var/lock/
subsys/ipsec, which allows local users to kill arbitrary processes by writing
a PID to a file, or possibly bypass disk quotas by writing arbitrary data to
a file, as demonstrated by files with 0666 permissions, a different
vulnerability than CVE-2011-1784.
References:
[1] http://lists.debian.org/debian-security/2011/05/msg00013.html
[2] http://lists.debian.org/debian-security/2011/05/msg00018.html
[3] http://lists.debian.org/debian-security/2011/05/msg00012.html
Discussion:
State
http://blogs.technet.com/b/srd/archive/2011/04/12/ms11-034-addressing-vulnerabilities-in-the-win32k-subsystem.aspxhttp://osvdb.org/71742http://secunia.com/advisories/44156http://support.avaya.com/css/P8/documents/100133352http://www.securityfocus.com/bid/47203http://www.securitytracker.com/id?1025345http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlhttp://www.vupen.com/english/advisories/2011/0952https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-034https://exchange.xforce.ibmcloud.com/vulnerabilities/66397https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12347http://blogs.technet.com/b/srd/archive/2011/04/12/ms11-034-addressing-vulnerabilities-in-the-win32k-subsystem.aspxhttp://osvdb.org/71742http://secunia.com/advisories/44156http://support.avaya.com/css/P8/documents/100133352http://www.securityfocus.com/bid/47203http://www.securitytracker.com/id?1025345http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlhttp://www.vupen.com/english/advisories/2011/0952https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-034https://exchange.xforce.ibmcloud.com/vulnerabilities/66397https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12347
2011-04-13
Published