CyberSec.Space Logo
返回 CVE 浏览器

CVE-2011-0654

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0040%
EPSS Percentile25.46th
Published2011年2月16日
Last Modified2026年4月29日

Vulnerability Description

Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.

Affected Platforms (CPE)

💻
Microsoft

Windows 2003 Server

All versions
💻
Microsoft

Windows 2003 Server

All versions
💻
Microsoft

Windows 2003 Server

All versions
💻
Microsoft

Windows 2003 Server

All versions
💻
Microsoft

Windows Server 2003

All versions
💻
Microsoft

Windows Server 2003

All versions

References & Advisories

相关漏洞威胁