PT-2011-2028 · Microsoft · Windows Server 2008 R2+3

Published

2011-02-09

·

Updated

2018-10-30

·

CVE-2011-0031

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2008 R2 and Windows 7 with JScript 5.8 and VBScript 5.8 scripting engines
Description The issue concerns the JScript 5.8 and VBScript 5.8 scripting engines in Microsoft Windows, which do not properly load decoded scripts from web pages. This allows remote attackers to trigger memory corruption, potentially leading to the disclosure of sensitive information through a crafted website.
Recommendations For Microsoft Windows Server 2008 R2 and Windows 7 with JScript 5.8 and VBScript 5.8, consider restricting access to web pages that could exploit this issue until a fix is available. As a temporary workaround, consider disabling the JScript 5.8 and VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0031

Affected Products

Jscript 5.8
Vbscript 5.8
Windows 7
Windows Server 2008 R2