CVE-2011-1229

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
microsoftCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
microsoftwindows_2003_server
-
microsoftwindows_7
-
microsoftwindows_7
-
microsoftwindows_server_2003
-
microsoftwindows_server_2008
-
microsoftwindows_server_2008
-
microsoftwindows_vista
-
microsoftwindows_vista
-
microsoftwindows_vista
-
microsoftwindows_vista
-
microsoftwindows_xp
-
microsoftwindows_xp
-
avayaagent_access
*
avayaaura_conferencing_standard_edition
6.0.0
avayabasic_call_management_system_reporting_desktop
*
avayacall_management_server_supervisor
*
avayacallpilot
4.0.x ≤
𝑥
≤ 5.0.x
avayacallvisor_asai_lan
*
avayacommunication_server_1000_telephony_manager
3.0.0 ≤
𝑥
≤ 4.0.0
avayacomputer_telephony
*
avayacontact_center_express
*
avayacustomer_interaction_express
*
avayaenterprise_manager
*
avayaintegrated_management
*
avayainteraction_center
*
avayaip_agent
*
avayaip_softphone
*
avayameeting_exchange
5.0.0 ≤
𝑥
≤ 5.2.0
avayamessaging_application_server
4.0.x ≤
𝑥
≤ 5.2.x
avayanetwork_reporting
*
avayaoctelaccess_server
*
avayaocteldesigner
*
avayaoperational_analyst
*
avayaoutbound_contact_management
*
avayaspeech_access
*
avayaunified_communication_center
*
avayaunified_messenger
*
avayavisual_messenger
*
avayavisual_vector_client
*
avayavpnmanager_console
*
avayaweb_messenger
*
𝑥
= Vulnerable software versions