PT-2011-2540 · Microsoft · Vbscript+1

Published

2011-04-13

·

Updated

2025-01-21

·

CVE-2011-0663

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft JScript versions 5.6 through 5.8 Microsoft VBScript versions 5.6 through 5.8
Description The issue is related to multiple integer overflows in the scripting engines, which allow remote attackers to execute arbitrary code via a crafted web page. This is referred to as a "Scripting Memory Reallocation" issue.
Recommendations For Microsoft JScript versions 5.6 through 5.8, consider disabling the scripting engine until a patch is available. For Microsoft VBScript versions 5.6 through 5.8, restrict access to the scripting engine to minimize the risk of exploitation.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2011-0663

Affected Products

Jscript
Vbscript