CVE-2011-2217

UnknownEPSS 41.96%

Last modified

CVE-2011-2217 is a vulnerability of currently unknown severity. Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.. EPSS estimates a 41.96% chance of exploitation in the next 30 days.

Description

Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.

Metrics

EPSS Probability
41.96%

98.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TomsawyerGet Extension Factory5.5.2.237
VmwareVirtual Infrastructure Client2.0.2
VmwareVirtual Infrastructure Client2.5
VmwareInfrastructure3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-2217?
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.
How severe is CVE-2011-2217?
Severity scoring for CVE-2011-2217 is pending analysis. The EPSS model estimates a 41.96% probability of exploitation in the next 30 days.
How do I fix CVE-2011-2217?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-2217?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST