Junglewise Threat Intelligence

CVE-2011-1889: Microsoft Forefront TMG Remote Code Execution Vulnerability

CVE-2011-1889 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Vendors: Microsoft.

Executive brief

A memory corruption vulnerability exists in the NSPLookupServiceNext function of the Microsoft Forefront Threat Management Gateway (TMG) 2010 Firewall Client. Remote attackers can exploit this via unspecified requests to execute arbitrary code in the security context of the client application.

Affected products

  • Microsoft Forefront Threat Management Gateway (TMG) 2010 2010

Timeline

  • 2011-06-14: patched: Microsoft Security Bulletin MS11-040 released.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: disclosed: NVD publication date.