CVE-2011-0663

HIGH

Microsoft JScript and VBScript 5.6-5.8 - Remote Code Execution via Integer Overflow

Title source: llm
STIX 2.1

Description

Multiple integer overflows in the Microsoft (1) JScript 5.6 through 5.8 and (2) VBScript 5.6 through 5.8 scripting engines allow remote attackers to execute arbitrary code via a crafted web page, aka "Scripting Memory Reallocation Vulnerability."

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/71774
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-102A.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0949
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025333
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/47249
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12673
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44162

Scores

CVSS v3 8.8
EPSS 0.2622
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-189 CWE-190
Status published
Products (6)
microsoft/jscript 5.6
microsoft/jscript 5.7
microsoft/jscript 5.8
microsoft/vbscript 5.6
microsoft/vbscript 5.7
microsoft/vbscript 5.8
Published Apr 13, 2011
Tracked Since Feb 18, 2026