cbcvebase.
CVE-2011-1213
published 2011-05-31

CVE-2011-1213: Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a…

PriorityP261critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
32.96%
98.2th percentile
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.

Affected

101 ranges· showing 25
VendorProductVersion rangeFixed in
ibmlotus_notes<= 8.5.2.2
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes

Detection & IOCsextracted from sources · hover to see the quote

filenamedata.lzh
other0x780c26b2
other0x60dc1043
pathlzhsr.dll
  • Detect malformed LZH file attachments with a crafted header triggering integer underflow in lzhsr.dll; monitor Lotus Notes processing of .lzh attachments for stack-based buffer overflow conditions.
  • Flag inbound email with .lzh attachments delivered to Lotus Notes 8.0.x through 8.5.2 FP2 endpoints; the exploit is delivered passively via email attachment.
  • Monitor for ROP gadget use in MSVCP60.dll (POP ECX; POP ECX; RETN at 0x780c26b2) and nnotes.dll (ADD ESP,52C gadget at 0x60dc1043) as indicators of exploitation attempts against this vulnerability.
  • Buffer overflow offset of 6741 (non-DEP) or 6745 (DEP bypass) bytes before the return address in the LZH parsing stack frame can be used to tune memory/heap spray detection signatures.
  • ·The Metasploit module targets Windows only; the ROP gadget addresses (0x780c26b2 in MSVCP60.dll and 0x60dc1043 in nnotes.dll) are version-specific and may not be reliable across all patch levels.
  • ·The exploit uses a passive stance, meaning it waits for the victim to open the malicious attachment rather than actively connecting; detection must account for file-based delivery rather than network-based exploitation.
  • ·EXITFUNC is set to 'process', meaning the exploit terminates the Notes process on exit; post-exploitation process crash of notes.exe may be an artifact of this technique.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.