CVE-2011-0037: Input Validation
Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0037?
CVE-2011-0037 has a medium severity rating, allowing local users to gain elevated privileges through a crafted value.
How do I fix CVE-2011-0037?
To fix CVE-2011-0037, upgrade the Microsoft Malware Protection Engine to version 1.1.6603.0 or later.
What products are affected by CVE-2011-0037?
CVE-2011-0037 affects Microsoft Malware Protection Engine, Microsoft Security Essentials, Windows Defender, and several others.
Can CVE-2011-0037 be exploited remotely?
CVE-2011-0037 cannot be exploited remotely as it requires local user access to the vulnerable system.
What are the consequences of CVE-2011-0037 exploitation?
Exploitation of CVE-2011-0037 could allow an attacker to gain unauthorized access and potentially execute arbitrary code with elevated privileges.