CVE-2011-2217 describes a critical vulnerability in specific ActiveX controls within Tom Sawyer GET Extension Factory 5.5.2.237, as integrated into VMware VI Client versions 2.0.2 and 2.5. This flaw allows remote attackers to execute arbitrary code or cause a denial of service through memory corruption when a user views a specially crafted HTML document in Internet Explorer. With a CVSS score of 9.3 (Critical) and an EPSS score indicating high exploitability, the vulnerability is easily exploitable over a network with medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, a Metasploit module exists for this vulnerability, and its FAUCET Risk Score of 100/100 indicates a high potential for exploitation, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.2.237CPE matchmatch criteria | cpe:2.3:a:tomsawyer:get_extension_factory:5.5.2.237:*:*:*:*:*:*:* | ||
2.0.2CPE matchmatch criteria | cpe:2.3:a:vmware:virtual_infrastructure_client:2.0.2:*:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:a:vmware:virtual_infrastructure_client:2.5:*:*:*:*:*:*:* | ||
3CPE matchmatch criteria | cpe:2.3:a:vmware:infrastructure:3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.