CVE Database
/

CVE-2011-0654

Back to search

CVE-2011-0654

Published: Feb 16, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.

VendorProductVersions

n/a

n/a

affected
n/a

References

TA11-102A
third-party-advisory
x_refsource_CERT
VU#323172
third-party-advisory
x_refsource_CERT-VN
16166
exploit
x_refsource_EXPLOIT-DB
ADV-2011-0394
vdb-entry
x_refsource_VUPEN
1025328
vdb-entry
x_refsource_SECTRACK
46360
vdb-entry
x_refsource_BID
ADV-2011-0938
vdb-entry
x_refsource_VUPEN
43299
third-party-advisory
x_refsource_SECUNIA
ms-win-server-browser-bo(65376)
vdb-entry
x_refsource_XF
MS11-019
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:12637
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now