CVE-2011-0657
CRITICALMicrosoft Windows DNS Client - Remote Code Execution via Crafted DNS Query
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-0657.
Includes Metasploit module auxiliary/dos/windows/llmnr/ms11_030_dnsapi.
AI-analyzed exploit summary This Metasploit module exploits a buffer underrun vulnerability in Microsoft's DNSAPI.dll via crafted LLMNR queries, leading to a DoS condition. It sends specially crafted IPv4 and IPv6 queries to trigger stack exhaustion.
Description
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
Exploits (1)
This Metasploit module exploits a buffer underrun vulnerability in Microsoft's DNSAPI.dll via crafted LLMNR queries, leading to a DoS condition. It sends specially crafted IPv4 and IPv6 queries to trigger stack exhaustion.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H