| MS11-037 |
The MHTML (Mime encapsulated HTML) protocol handler is vulnerable to information disclosure through an XSS like problem.
Replaces MS11-026. |
MHTML
CVE-2011-1894 |
KB 2544893 |
Publicly known vulnerability. |
Severity:Important
Exploitability:3 |
Important |
Low |
| MS11-038 |
WMF processing by OLE allows for arbitrary code execution with the rights of the logged on user.
Replaces MS08-008. |
OLE - WMF
CVE-2011-0658 |
KB 2476490 |
No known exploits |
Severity:Critical
Exploitability:1 |
Critical |
Important |
| MS11-039 |
Input validation vulnerabilities in the .NET
framework and the Silverlight implementations allow for arbitrary code
execution with the rights of the logged on user. |
.NET - silverlight
CVE-2011-0664 |
KB 2514842 |
No known exploits |
Severity:Critical
Exploitability:1 |
Critical |
Important |
| MS11-040 |
Improper bounds checking in Microsoft
Forefront Threat Management Gateway 2010 Client allows for arbitrary
code execution in the context of the service. |
Forefront TMG
CVE-2011-1889 |
KB 2520426 |
No known exploits |
Severity:Critical
Exploitability:1 |
Critical |
Important |
| MS11-041 |
An input validation problem in the parsing
of OTF (OpenType Font) fonts in in 64bit kernels allows for arbitrary
code execution in kernel mode. This is remotely exploitable though file
sharing, webdav, websites, email and more.
Replaces MS11-034. |
OTF
CVE-2011-1873 |
KB 2525694 |
No known exploits |
Severity:Critical
Exploitability:2 |
Critical |
Important |
| MS11-042 |
Input validation problems in the Distributed
File System (DFS) implementation allow for arbitrary code execution in
the context of the service or denial of service (DoS) conditions. |
DFS (Distributed File System)
CVE-2011-1868
CVE-2011-1869 |
KB 2535512 |
No known exploits |
Severity:Critical
Exploitability:1-3 |
Critical |
Critical |
| MS11-043 |
An input validation problem in the parsing
of the responses to SMB requests allows for arbitrary code execution in
the context of the service.
Replaces MS11-019 and MS10-020. |
SMB
CVE-2011-1268 |
KB 2536276 |
No known exploits |
Severity:Critical
Exploitability:1 |
Critical |
Important |
| MS11-044 |
An input validation problem in the JIT
optimization of the .NET framework allows for arbitrary code execution
in the context of the logged on user, and bypass security measures such
as the CAS (Code Access Security) restrictions.
Replaces MS11-028 and MS10-060. |
.NET
CVE-2011-1271 |
KB 2538814 |
Publicly disclosed vulnerability. |
Severity:Critical
Exploitability:2 |
Critical |
Critical |
| MS11-045 |
Multiple vulnerabilities in Excel allow for arbitrary code execution in the context of the logged on user.
Office for Mac versions are also affected.
Replaces MS11-021 and MS11-022. |
Excel
CVE-2011-1272
CVE-2011-1273
CVE-2011-1274
CVE-2011-1275
CVE-2011-1276
CVE-2011-1277
CVE-2011-1278
CVE-2011-1279 |
KB 2537146 |
No known exploits |
Severity:Important
Exploitability:1-3 |
Critical |
Important |
| MS11-046 |
An input validation vulnerability in AFD
(Ancillary Function Driver) allows for privilege escalation and
arbitrary code execution in kernel mode for logged on users.
Replaces MS10-066. |
AFD
CVE-2011-1249 |
KB 2503665 |
Publicly disclosed vulnerability, Microsoft claims "limited, targeted attacks attempting to exploit the vulnerability" |
Severity:Important
Exploitability:1 |
Critical |
Critical |
| MS11-047 |
A Denial of Service (DoS) condition is
possible where an authenticated user of a guest system can cause a
denial of service on the host system.
Replaces MS10-102. |
Hyper-V
CVE-2011-1872 |
KB 2525835 |
No known exploits. |
Severity:Important
Exploitability:3 |
Low |
Important |
| MS11-048 |
A parsing error in the SMB server can be used to cause a Denial of Service (DoS) condition.
Replaces MS09-050. |
SMB server
CVE-2011-1267 |
KB 2525835 |
No known exploits. |
Severity:Important
Exploitability:3 |
Low |
Important |
| MS11-049 |
XML editor can leak file content though XML
external entities that are nested. XML editor is part of Infopath,
SQL server, and Visual Studio.
Replaces MS10-039 and MS09-062. |
XML editor
CVE-2011-1280 |
KB 2543893 |
No known exploits. |
Severity:Important
Exploitability:3 |
Important |
Important |
| MS11-050 |
Multitude of vulnerabilities in MSIE.
Replaces MS11-018. |
MSIE
CVE-2011-1246
CVE-2011-1250
CVE-2011-1251
CVE-2011-1252
CVE-2011-1254
CVE-2011-1255
CVE-2011-1256
CVE-2011-1258
CVE-2011-1260
CVE-2011-1261
CVE-2011-1262 |
KB 2543893 |
No known exploits. |
Severity:Critical
Exploitability:1-3 |
Critical |
Important |
| MS11-051 |
Active Directory Certificate Services Web Enrollment allows for a reflected XSS issue. |
Active Directory Certificate Services Web Enrollment
CVE-2011-1264 |
KB 2518295 |
No known exploits. |
Severity:Important
Exploitability:1 |
N/A |
Important |
| MS11-052 |
A VML memory corruption allows arbitrary code execution in MSIE with the rights of the logged on user. IE9 is not affected. |
VML - MSIE
CVE-2011-1266 |
KB 2544521 |
No known exploits. |
Severity:Critical
Exploitability:1 |
Critical |
Important |