7.2

CVE-2011-1229

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows 2003 Server Version- Updatesp2
MicrosoftWindows 7 Version-
MicrosoftWindows 7 Version- Updatesp1
MicrosoftWindows Server 2003 Version- Updatesp2
MicrosoftWindows Server 2008 Version- Updatesp2
MicrosoftWindows Server 2008 Versionr2 HwPlatformitanium
MicrosoftWindows Server 2008 Versionr2 HwPlatformx64
MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformitanium
MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
MicrosoftWindows Vista Version- Updatesp1
MicrosoftWindows Vista Version- Updatesp1 HwPlatformx64
MicrosoftWindows Vista Version- Updatesp2
MicrosoftWindows Vista Version- Updatesp2 HwPlatformx64
MicrosoftWindows Xp Version- Updatesp2 HwPlatformx64
MicrosoftWindows Xp Version- Updatesp3
AvayaCallpilot Version >= 4.0.x <= 5.0.x
AvayaCommunication Server 1000 Telephony Manager Version >= 3.0.0 <= 4.0.0
AvayaMeeting Exchange Version >= 5.0.0 <= 5.2.0
AvayaMessaging Application Server Version >= 4.0.x <= 5.2.x
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.724
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.