CVE-2011-1889
CRITICALCISA KEVEPSS 99th pctlDescription
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit Intelligence
Very high risk: more likely to be exploited than 99% of all known CVEs.
Microsoft Forefront TMG Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
Apply updates per vendor instructions.
Remediation due: 2022-03-24
References
- http://secunia.com/advisories/44857
- http://www.securityfocus.com/bid/48181
- http://www.securitytracker.com/id?1025637
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67736
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12642
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-1889
Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
Start freeThis product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-04-22.