peter bassill · operator
$ cve CVE-2011-0045 JSON

CVE-2011-0045 EXPLOIT

7.2
HIGH · CVSS 2.0 · EPSS 3.8% (pctl 90)

Patch early

A public exploit exists.

Description

The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges via a crafted application, related to WmiTraceMessageVa, aka "Windows Kernel Integer Truncation Vulnerability."

Scoring

CVSS7.2 (HIGH, v2.0)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS3.8% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2011-02-09
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD