First published: Fri Feb 25 2011(Updated: )
Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Forefront Client Security | ||
Microsoft Forefront Endpoint Protection 2010 | ||
Microsoft Malicious Software Removal Tool | ||
Microsoft Malware Protection Engine | <=1.1.6502.0 | |
Microsoft Malware Protection Engine | =0.1.13.192 | |
Microsoft Malware Protection Engine | =1.1.3520.0 | |
Microsoft Security Essentials | ||
Microsoft Windows Defender | ||
Microsoft Windows Live OneCare |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0037 has a medium severity rating, allowing local users to gain elevated privileges through a crafted value.
To fix CVE-2011-0037, upgrade the Microsoft Malware Protection Engine to version 1.1.6603.0 or later.
CVE-2011-0037 affects Microsoft Malware Protection Engine, Microsoft Security Essentials, Windows Defender, and several others.
CVE-2011-0037 cannot be exploited remotely as it requires local user access to the vulnerable system.
Exploitation of CVE-2011-0037 could allow an attacker to gain unauthorized access and potentially execute arbitrary code with elevated privileges.