CVE Feed

    Dashboard / CVE / CVE-2011-1229

    CVE-2011-1229

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."

    Published:Apr 13, 2011
    Last Modified:Apr 11, 2025
    EPS:Apr 13, 2011
    EPSS Score:0.00689
    CVSS Score:7.2

    Affected Products

    Vendor
    Avaya
    Product
    Agent Access
    Vendor
    Avaya
    Product
    Aura Conferencing Standard Edition
    Vendor
    Avaya
    Product
    Basic Call Management System Reporting Desktop
    Vendor
    Avaya
    Product
    Call Management Server Supervisor
    Vendor
    Avaya
    Product
    Callpilot
    Vendor
    Avaya
    Product
    Callvisor Asai Lan
    Vendor
    Avaya
    Product
    Communication Server 1000 Telephony Manager
    Vendor
    Avaya
    Product
    Computer Telephony
    Vendor
    Avaya
    Product
    Contact Center Express
    Vendor
    Avaya
    Product
    Customer Interaction Express
    Vendor
    Avaya
    Product
    Enterprise Manager
    Vendor
    Avaya
    Product
    Integrated Management
    Vendor
    Avaya
    Product
    Interaction Center
    Vendor
    Avaya
    Product
    Ip Agent
    Vendor
    Avaya
    Product
    Ip Softphone
    Vendor
    Avaya
    Product
    Meeting Exchange
    Vendor
    Avaya
    Product
    Messaging Application Server
    Vendor
    Avaya
    Product
    Network Reporting
    Vendor
    Avaya
    Product
    Octelaccess Server
    Vendor
    Avaya
    Product
    Octeldesigner
    Vendor
    Avaya
    Product
    Operational Analyst
    Vendor
    Avaya
    Product
    Outbound Contact Management
    Vendor
    Avaya
    Product
    Speech Access
    Vendor
    Avaya
    Product
    Unified Communication Center
    Vendor
    Avaya
    Product
    Unified Messenger
    Vendor
    Avaya
    Product
    Visual Messenger
    Vendor
    Avaya
    Product
    Visual Vector Client
    Vendor
    Avaya
    Product
    Vpnmanager Console
    Vendor
    Avaya
    Product
    Web Messenger
    Vendor
    Microsoft
    Product
    Windows 2003 Server
    Vendor
    Microsoft
    Product
    Windows 7
    Vendor
    Microsoft
    Product
    Windows Server 2003
    Vendor
    Microsoft
    Product
    Windows Server 2008
    Vendor
    Microsoft
    Product
    Windows Vista
    Vendor
    Microsoft
    Product
    Windows Xp

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High