CVE-2011-1229
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD
Description
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
Affected (45)
Products: Microsoft: Windows 2003 Server, Windows 7, Windows Server 2003, Windows Server 2008, Windows Vista, Windows Xp · Avaya: Agent Access, Aura Conferencing Standard Edition, Basic Call Management System Reporting Desktop, Call Management Server Supervisor, Callpilot, Callvisor Asai Lan, Communication Server 1000 Telephony Manager, Computer Telephony, Contact Center Express, Customer Interaction Express, Enterprise Manager, Integrated Management, Interaction Center, Ip Agent, Ip Softphone, Meeting Exchange, Messaging Application Server, Network Reporting, Octelaccess Server, Octeldesigner, Operational Analyst, Outbound Contact Management, Speech Access, Unified Communication Center, Unified Messenger, Visual Messenger, Visual Vector Client, Vpnmanager Console, Web Messenger
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 6.0.0 | |
| All versions | |
| All versions | |
| From 4.0.x to 5.0.x | |
| All versions | |
| From 3.0.0 to 4.0.0 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| From 5.0.0 to 5.2.0 | |
| From 4.0.x to 5.2.x | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Related CWEs
References (22)
Source: secure@microsoft.com
Vendor Advisory
Source: secure@microsoft.com
Third Party AdvisoryUS Government Resource
Source: secure@microsoft.com
PatchVendor Advisory
Source: secure@microsoft.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.