CVE-2011-5046
CVE-2011-5046
9.3
CriticalPublished:
Last updated:
Source:cve@mitre.org
Modified
Weakness (CWE)
CVSS Vector
v2.0- Attack Vector
- Network
- Attack Complexity
- Medium
- Authentication
- None
- Confidentiality
- Complete
- Integrity
- Complete
- Availability
- Complete
Description
The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
Exploits
References
cve@mitre.org
http://osvdb.org/77908cve@mitre.org
http://secunia.com/advisories/47237cve@mitre.org
http://www.exploit-db.com/exploits/18275cve@mitre.org
http://www.securitytracker.com/id?1026450cve@mitre.org
http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlcve@mitre.org
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14603af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/77908af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/47237af854a3a-2127-422b-91ae-364da2661108
http://twitter.com/w3bd3vil/statuses/148454992989261824af854a3a-2127-422b-91ae-364da2661108
http://www.exploit-db.com/exploits/18275af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1026450af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlaf854a3a-2127-422b-91ae-364da2661108
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-008af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/71873af854a3a-2127-422b-91ae-364da2661108
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14603