CVE-2011-1889Patch(microsoft / forefront_threat_management_gateway)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft forefront_threat_management_gateway systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-03-24. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forefront_threat_management_gateway

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
forefront_threat_management_gateway

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-29: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 104-29
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2011-1889 (CVSS 9.8) - Microsoft Forefront TMG 2010 Firewall Client memory corruption vulnerability allows remote code execution. Network-based attack, no user interaction required. Patch immediately if still deployed. #CVE #PatchNow https://t.co/1rMfnAr8Zc

    Post summary

    The tweet announces CVE-2011-1889 as a critical remote code execution flaw in Microsoft Forefront TMG 2010 and urges immediate patching, with no mention of PoC, exploit code, or active attacks.

    0000028
    9 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftforefront_threat_management_gateway2010--

Explore more