CVE-2011-1248 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 47.6% (pctl 99)
Patch early
A public exploit exists.
Description
WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 47.57% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-05-13 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft WINS Service 5.2.3790.4520 - Memory Corruption (MS11-035) | 2011-09-13 |
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-035
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12724
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-035
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12724
→ the Explorer · watch your stack · NVD