CVE-2011-0037
Summary
| CVE | CVE-2011-0037 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-25 18:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Forefront Client Security | All | All | All | All |
| Application | Microsoft | Forefront Endpoint Protection 2010 | - | All | All | All |
| Application | Microsoft | Malicious Software Removal Tool | All | All | All | All |
| Application | Microsoft | Malware Protection Engine | 0.1.13.192 | All | All | All |
| Application | Microsoft | Malware Protection Engine | 1.1.3520.0 | All | All | All |
| Application | Microsoft | Malware Protection Engine | All | All | All | All |
| Application | Microsoft | Security Essentials | All | All | All | All |
| Application | Microsoft | Windows Defender | All | All | All | All |
| Application | Microsoft | Windows Live Onecare | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Malware Protection Engine Registry Processing Error Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Microsoft Malware Protection Engine Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Microsoft Products Malware Protection Engine Privilege Escalation - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Microsoft Security Advisory (2491888): Vulnerability in Microsoft Malware Protection Engine Could Allow Elevation of Privilege | af854a3a-2127-422b-91ae-364da2661108 | www.microsoft.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.