PT-2011-4430 · Microsoft · Windows Xp+3

Published

2011-12-13

·

Updated

2019-02-26

·

CVE-2011-3397

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP versions SP2 through SP3 Microsoft Server 2003 version SP2
Description A remote code execution issue exists in the Microsoft Time component, allowing attackers to execute arbitrary code via a crafted web site. An attacker could exploit this by constructing a specially crafted Web page, potentially gaining the same user rights as the logged-on user when a user views the page.
Recommendations For Microsoft Windows XP versions SP2 through SP3, consider restricting access to the Microsoft Time component until a fix is available. For Microsoft Server 2003 version SP2, avoid using the affected component in Internet Explorer to minimize the risk of exploitation.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3397

Affected Products

Internet Explorer
Server 2003
Windows Xp
Windows