CVE-2011-4434
Windows 7 and Server 2008 R2 - AppLocker Rule Bypass via Macro or Scripting Feature
Title source: llmDescription
Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_mskb
http://support.microsoft.com/kb/2532445
Scores
EPSS
0.0185
EPSS Percentile
76.9%
Details
CWE
CWE-264
Status
published
Products (2)
microsoft/windows_7
(4 CPE variants)
microsoft/windows_server_2008
r2 (2 CPE variants)
Published
Nov 11, 2011
Tracked Since
Feb 18, 2026