CVE-2011-2217

HIGH

Description

Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.

References

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=911

http://secunia.com/advisories/44826

http://secunia.com/advisories/44844

http://securitytracker.com/id?1025602

http://www.securityfocus.com/bid/48099

http://www.vmware.com/security/advisories/VMSA-2011-0009.html

https://exchange.xforce.ibmcloud.com/vulnerabilities/67816

Details

Source: MITRE

Published: 2011-06-06

Updated: 2017-08-29

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (3 total)

IDNameProductFamilySeverity
89678VMware ESX / ESXi Multiple Vulnerabilities (VMSA-2011-0009) (remote check)NessusMisc.
high
54990Tom Sawyer Software GET Extension Factory COM Object Instantiation Memory CorruptionNessusWindows
high
54968VMSA-2011-0009 : VMware hosted product updates, ESX patches and VI Client update resolve multiple security issuesNessusVMware ESX Local Security Checks
high