CRITICAL

CVE-2011-1930

CVSS v3

9.8

CRITICAL

EPSS Score

29.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

Technical details

Published
11/14/2019
Exploit-DB
EDB-35785

Frequently asked questions

What is CVE-2011-1930?

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

Is CVE-2011-1930 actively exploited?

Active exploitation of CVE-2011-1930 has not been confirmed. The EPSS score is 29.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2011-1930?

CVE-2011-1930 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2011-1930 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

Other 2011 vulnerabilities worth triaging

Ranked by exploit probability (EPSS).