{"api_version":"1","generated_at":"2026-07-23T07:30:12+00:00","cve":"CVE-2011-1056","urls":{"html":"https://cve.report/CVE-2011-1056","api":"https://cve.report/api/cve/CVE-2011-1056.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1056","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1056"},"summary":{"title":"CVE-2011-1056","description":"The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-02-21 21:00:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.2","severity":"","vector":"AV:L/AC:H/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:H/Au:N/C:C/I:C/A:C","baseScore":6.2,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/43166","name":"http://secunia.com/advisories/43166","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Metasploit Framework Insecure Filesystem Permissions Security Issue - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/70857","name":"http://osvdb.org/70857","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2011/0371","name":"http://www.vupen.com/english/advisories/2011/0371","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blog.metasploit.com/2011/02/metasploit-framework-352-released.html","name":"http://blog.metasploit.com/2011/02/metasploit-framework-352-released.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Rapid7 Community: Community: Metasploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1056","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1056","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1056","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"metasploit","cpe5":"metasploit_framework","cpe6":"3.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1056","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:14:27.242Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"70857","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/70857"},{"name":"ADV-2011-0371","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0371"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blog.metasploit.com/2011/02/metasploit-framework-352-released.html"},{"name":"43166","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43166"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-02-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-03-11T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"70857","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/70857"},{"name":"ADV-2011-0371","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0371"},{"tags":["x_refsource_CONFIRM"],"url":"http://blog.metasploit.com/2011/02/metasploit-framework-352-released.html"},{"name":"43166","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43166"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-1056","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"70857","refsource":"OSVDB","url":"http://osvdb.org/70857"},{"name":"ADV-2011-0371","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0371"},{"name":"http://blog.metasploit.com/2011/02/metasploit-framework-352-released.html","refsource":"CONFIRM","url":"http://blog.metasploit.com/2011/02/metasploit-framework-352-released.html"},{"name":"43166","refsource":"SECUNIA","url":"http://secunia.com/advisories/43166"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-1056","datePublished":"2011-02-21T20:00:00.000Z","dateReserved":"2011-02-21T00:00:00.000Z","dateUpdated":"2024-08-06T22:14:27.242Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-02-21 21:00:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:H/Au:N/C:C/I:C/A:C","baseScore":6.2,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":1.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:metasploit:metasploit_framework:3.5.1:*:*:*:*:*:*:*","matchCriteriaId":"C1D5B5D1-4A4D-46B8-A65E-5903BA2C6875"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1056","Ordinal":"1","Title":"CVE-2011-1056","CVE":"CVE-2011-1056","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1056","Ordinal":"1","NoteData":"The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse.","Type":"Description","Title":"CVE-2011-1056"},{"CveYear":"2011","CveId":"1056","Ordinal":"2","NoteData":"2011-02-21","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1056","Ordinal":"3","NoteData":"2011-03-11","Type":"Other","Title":"Modified"}]}}}