Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-2217Improper Restriction of Operations within the Bounds of a Memory Buffer in GET Extension Factory

Severity
9.3CRITICALNVD
EPSS
88.1%
top 0.51%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 6
Latest updateMay 17

Description

Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-pmh8-qf2w-qvjq: Certain ActiveX controls in (1) tsgetxu71ex5522022-05-17
CVEList
CVE-2011-2217: Certain ActiveX controls in (1) tsgetxu71ex5522011-06-06

💥Exploits & PoCs

1
Exploit-DB
Tom Sawyer Software GET Extension Factory - Remote Code Execution (Metasploit)2012-06-10
CVE-2011-2217 — GET Extension Factory vulnerability | cvebase