CVE-2011-2013

CRITICAL

Microsoft Windows - Buffer Overflow

Title source: llm

Description

Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · cdoswindows
https://www.exploit-db.com/exploits/36285

Scores

CVSS v3 9.8
EPSS 0.4283
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190 CWE-189
Status published
Products (4)
microsoft/windows_7 (3 CPE variants)
microsoft/windows_server_2008 (3 CPE variants)
microsoft/windows_server_2008 r2 (2 CPE variants)
microsoft/windows_vista
Published Nov 08, 2011
Tracked Since Feb 18, 2026