VulnerabilityAnalyzed
CVE-2011-1889
Microsoft Forefront TMG Remote Code Execution Vulnerability
KEVCRITICAL 9.8EPSS 48.4%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 48.37% probability · 99th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Weakness
- CWE-119
- Affected
- microsoft/forefront threat management gateway
- Source
- secure@microsoft.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2011-1889
References
- http://secunia.com/advisories/44857Broken Link
- http://www.securityfocus.com/bid/48181Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1025637Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-040Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67736Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12642Broken Link
- http://secunia.com/advisories/44857Broken Link
- http://www.securityfocus.com/bid/48181Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1025637Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-040Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67736Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12642Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-1889US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.