CVE-2011-1056: Medium severity rapid7 metasploit vulnerability
The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1056?
CVE-2011-1056 has a medium severity rating due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2011-1056?
To fix CVE-2011-1056, ensure that the installation directory for Metasploit Framework 3.5.1 has the correct permissions set to restrict file modifications.
Who is affected by CVE-2011-1056?
Users running Metasploit Framework version 3.5.1 on Windows are affected by CVE-2011-1056.
What type of attack does CVE-2011-1056 enable?
CVE-2011-1056 enables local users to execute a privilege escalation attack by replacing critical files in the Metasploit installation directory.
What is the potential impact of CVE-2011-1056?
The potential impact of CVE-2011-1056 includes unauthorized access to elevated privileges which could lead to further system compromises.