CVE-2011-1889
CRITICAL KEVMicrosoft Forefront TMG 2010 - RCE
Title source: llmDescription
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
References (7)
Scores
CVSS v3
9.8
EPSS
0.8724
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-03-03
VulnCheck KEV
2022-03-03
InTheWild.io
2022-03-03
ENISA EUVD
EUVD-2011-1887
CWE
CWE-119
Status
published
Products (1)
microsoft/forefront_threat_management_gateway
2010
Published
Jun 16, 2011
KEV Added
Mar 03, 2022
Tracked Since
Feb 18, 2026