CVE-2011-0037
Summary
| CVE | CVE-2011-0037 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-25 18:00:00 UTC |
| Updated | 2017-08-17 01:33:00 UTC |
| Description | Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Forefront Client Security | All | All | All | All |
| Application | Microsoft | Forefront Client Security | All | All | All | All |
| Application | Microsoft | Forefront Endpoint Protection 2010 | - | All | All | All |
| Application | Microsoft | Forefront Endpoint Protection 2010 | - | All | All | All |
| Application | Microsoft | Malicious Software Removal Tool | All | All | All | All |
| Application | Microsoft | Malicious Software Removal Tool | All | All | All | All |
| Application | Microsoft | Malware Protection Engine | 0.1.13.192 | All | All | All |
| Application | Microsoft | Malware Protection Engine | 1.1.3520.0 | All | All | All |
| Application | Microsoft | Malware Protection Engine | 0.1.13.192 | All | All | All |
| Application | Microsoft | Malware Protection Engine | 1.1.3520.0 | All | All | All |
| Application | Microsoft | Malware Protection Engine | All | All | All | All |
| Application | Microsoft | Security Essentials | All | All | All | All |
| Application | Microsoft | Security Essentials | All | All | All | All |
| Application | Microsoft | Windows Defender | All | All | All | All |
| Application | Microsoft | Windows Defender | All | All | All | All |
| Application | Microsoft | Windows Live Onecare | All | All | All | All |
| Application | Microsoft | Windows Live Onecare | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Products Malware Protection Engine Privilege Escalation - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| Microsoft Security Advisory (2491888): Vulnerability in Microsoft Malware Protection Engine Could Allow Elevation of Privilege | CONFIRM | www.microsoft.com | Vendor Advisory |
| Microsoft Malware Protection Engine Local Privilege Escalation Vulnerability | BID | www.securityfocus.com | |
| Microsoft Malware Protection Engine Registry Processing Error Lets Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | securitytracker.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.