PT-2011-2755 · Ibm · Ibm Lotus Notes

Rgod

·

Published

2011-02-07

·

Updated

2017-09-19

·

CVE-2011-0912

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Lotus Notes versions 8.0.x through 8.0.2 FP5 IBM Lotus Notes versions 8.5.x through 8.5.1 FP4
Description The issue allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file.
Recommendations For IBM Lotus Notes versions 8.0.x through 8.0.2 FP5, update to version 8.0.2 FP6 or later. For IBM Lotus Notes versions 8.5.x through 8.5.1 FP4, update to version 8.5.1 FP5 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0912
ZDI-11-051

Affected Products

Ibm Lotus Notes