CVE-2011-0901 describes multiple stack-based buffer overflows in the tsc_launch_remote function of Terminal Server Client (tsclient) 0.150, and potentially other versions. This vulnerability allows user-assisted remote attackers to execute arbitrary code by providing a specially crafted .RDP file containing an overly long username, password, or domain argument. With a CVSS score of 6.8 (Medium), successful exploitation could lead to partial compromise of confidentiality, integrity, and availability, requiring user interaction and network access. While a Denial of Service exploit exists on ExploitDB, there is no evidence of active exploitation, Metasploit modules, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.150CPE matchmatch criteria | cpe:2.3:a:erick_woods:terminal_server_client:0.150:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.