CVE-2011-1889

CRITICAL KEV

Microsoft Forefront TMG 2010 - RCE

Title source: llm

Description

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."

Scores

CVSS v3 9.8
EPSS 0.8724
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-03
VulnCheck KEV 2022-03-03
InTheWild.io 2022-03-03
ENISA EUVD EUVD-2011-1887
CWE
CWE-119
Status published
Products (1)
microsoft/forefront_threat_management_gateway 2010
Published Jun 16, 2011
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026