CVE-2011-0031
The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 17.03% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/windows 7 · microsoft/windows server 2008
- Source
- secure@microsoft.com
References
- http://osvdb.org/70827
- http://secunia.com/advisories/43249Vendor Advisory
- http://www.securityfocus.com/bid/46139
- http://www.securitytracker.com/id?1025044
- http://www.vupen.com/english/advisories/2011/0322Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-009
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64919
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12313
- http://osvdb.org/70827
- http://secunia.com/advisories/43249Vendor Advisory
- http://www.securityfocus.com/bid/46139
- http://www.securitytracker.com/id?1025044
- http://www.vupen.com/english/advisories/2011/0322Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-009
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64919
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12313
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.