VULNERABILITY INTELLIGENCE

CVE-2011-0045

CVSS score7.2 HIGH
EPSS probability3.80%
CISA KEVNot currently listed
Published2011-02-09
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C

Description

The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges via a crafted application, related to WmiTraceMessageVa, aka "Windows Kernel Integer Truncation Vulnerability."

Weakness classification

  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Primary references