CVE Feed

    Dashboard / CVE / CVE-2011-2217

    CVE-2011-2217

    Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.

    Published:Jun 6, 2011
    Last Modified:Apr 11, 2025
    EPS:Jun 6, 2011
    EPSS Score:0.88252
    CVSS Score:9.3

    Affected Products

    Vendor
    Tomsawyer
    Product
    Get Extension Factory
    Vendor
    Vmware
    Product
    Infrastructure
    Vendor
    Vmware
    Product
    Virtual Infrastructure Client

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High