Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in...
Vulnerability Description
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2217
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67816
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=911
- http://secunia.com/advisories/44844
- http://www.vmware.com/security/advisories/VMSA-2011-0009.html
- http://www.securityfocus.com/bid/48099
- http://secunia.com/advisories/44826
- http://securitytracker.com/id?1025602
Affected Vendor
tomsawyer
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.