CVE-2011-1213
published 2011-05-31CVE-2011-1213: Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a…
PriorityP261critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
32.96%
98.2th percentile
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | lotus_notes | <= 8.5.2.2 | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
| ibm | lotus_notes | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect malformed LZH file attachments with a crafted header triggering integer underflow in lzhsr.dll; monitor Lotus Notes processing of .lzh attachments for stack-based buffer overflow conditions. ↗
- →Flag inbound email with .lzh attachments delivered to Lotus Notes 8.0.x through 8.5.2 FP2 endpoints; the exploit is delivered passively via email attachment. ↗
- →Monitor for ROP gadget use in MSVCP60.dll (POP ECX; POP ECX; RETN at 0x780c26b2) and nnotes.dll (ADD ESP,52C gadget at 0x60dc1043) as indicators of exploitation attempts against this vulnerability. ↗
- →Buffer overflow offset of 6741 (non-DEP) or 6745 (DEP bypass) bytes before the return address in the LZH parsing stack frame can be used to tune memory/heap spray detection signatures. ↗
- ·The Metasploit module targets Windows only; the ROP gadget addresses (0x780c26b2 in MSVCP60.dll and 0x60dc1043 in nnotes.dll) are version-specific and may not be reliable across all patch levels. ↗
- ·The exploit uses a passive stance, meaning it waits for the victim to open the malicious attachment rather than actively connecting; detection must account for file-based delivery rather than network-based exploitation. ↗
- ·EXITFUNC is set to 'process', meaning the exploit terminates the Notes process on exit; post-exploitation process crash of notes.exe may be an artifact of this technique. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Lotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)
exploitdb·2011-06-23
CVE-2011-1213 Lotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)
Lotus Notes 8.0.x 'Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview(.lzh attachment)',
'Description' => %q{
This module exploits a stack buffer overflow in Lotus Notes 8.5.2 when
parsing a malformed, specially crafted LZH file. This vulnerability was
discovered binaryhouse.net
},
'License' => MSF_LICENSE,
'Author' =>
[
'binaryhouse.net', # original discovery
'alino ', # Metasploit module
],
'Version' => '$Revision: 13015 $',
'References' =>
[
['CVE', '2011-1213'],
['OSVDB', '72706'],
['BID', '48018'],
['URL', 'http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=904'],
['URL', 'http://www.ibm.com/support/docview.wss?uid=swg21500034'],
],
'Stance' => Msf::Exploit::Stance::Passive,
'DefaultOptions' =>
{
'EXITFUNC' => 'process',
},
'Platform' => ['win'],
'Targets' =>
[
[ 'Lot
Metasploit
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
metasploit
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
This module exploits a stack buffer overflow in Lotus Notes 8.5.2 when parsing a malformed, specially crafted LZH file. This vulnerability was discovered binaryhouse.net
No writeups or analysis indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=904http://secunia.com/advisories/44624http://securityreason.com/securityalert/8285http://www.ibm.com/support/docview.wss?uid=swg21500034http://www.securityfocus.com/bid/47962https://exchange.xforce.ibmcloud.com/vulnerabilities/67620https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14634http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=904http://secunia.com/advisories/44624http://securityreason.com/securityalert/8285http://www.ibm.com/support/docview.wss?uid=swg21500034http://www.securityfocus.com/bid/47962https://exchange.xforce.ibmcloud.com/vulnerabilities/67620https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14634
2011-05-31
Published