Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-2003Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Windows Server 2008

Severity
9.3CRITICALNVD
GHSA6.5
EPSS
49.4%
top 2.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 12
Latest updateMay 13

Description

Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-rr89-f283-c7m9: Buffer overflow in win32k2022-05-13
GHSA
JBossWS vulnerable to uncontrolled recursion2022-05-13

💥Exploits & PoCs

25
Exploit-DB
Microsoft Windows (x86) - 'NDISTAPI' Local Privilege Escalation (MS11-062)2016-10-24
Exploit-DB
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)2016-10-18
Exploit-DB
HP Data Protector - CMD Install Service (Metasploit)2013-08-02
Exploit-DB
Enterasys NetSight - 'nssyslogd.exe' Remote Buffer Overflow (Metasploit)2013-01-04
Exploit-DB
HP Data Protector Client - EXEC_CMD Remote Code Execution2012-06-19

📋Vendor Advisories

4
Red Hat
JBossWS remote Denial of Service2011-09-15
Red Hat
ruby: Properly initialize the random number generator when forking new process2011-07-02
Red Hat
ruby: Properly initialize the random number generator when forking new process2011-07-02
Red Hat
jabberd: DoS via the XML "billion laughs attack"2011-05-31

🕵️Threat Intelligence

1
Zscaler
Zscaler found Multiple Security Vulnerabilities | 11-11-2011

💬Community

2
Bugzilla
CVE-2012-0039 glib2: hash table collisions CPU usage DoS2012-01-09
Bugzilla
CVE-2011-4079 openldap: one-byte buffer overflow in slapd2011-10-26