9.3
CVE-2011-5046
- EPSS 45.03%
- Veröffentlicht 30.12.2011 19:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:50
- Erkennungen
The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update sp2
Microsoft ≫ Windows Server 2008 Version r2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 45.03% | 0.987 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.us-cert.gov/cas/techalerts/TA12-045A.html
http://osvdb.org/77908
http://secunia.com/advisories/47237
http://twitter.com/w3bd3vil/statuses/148454992989261824
http://www.exploit-db.com/exploits/18275
http://www.securitytracker.com/id?1026450
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-008
https://exchange.xforce.ibmcloud.com/vulnerabilities/71873
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14603