Vulnerability record · CVE-2011-0654 · published 16 February 2011
CVE-2011-0654: Windows CIFS browser service integer underflow leads to heap overflow
Microsoft · Windows 2003 Server
An integer underflow in the BowserWriteErrorLogEntry function of the CIFS browser service (Mrxsmb.sys/bowser.sys) in multiple Windows versions causes a heap-based buffer overflow when a malformed BROWSER ELECTION message is processed. Because the flaw is remotely reachable without authentication and can lead to code execution, it is a serious pre-auth network risk for unpatched legacy Windows hosts.
Description
Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityPre-auth remote code execution with public exploit code and very high EPSS, though not observed in KEV or ransomware campaigns.
What it is
An integer underflow in the BowserWriteErrorLogEntry function of the CIFS browser service (Mrxsmb.sys/bowser.sys) in multiple Windows versions causes a heap-based buffer overflow when a malformed BROWSER ELECTION message is processed. Because the flaw is remotely reachable without authentication and can lead to code execution, it is a serious pre-auth network risk for unpatched legacy Windows hosts.
Impact
A remote attacker can execute arbitrary code with system privileges or crash the affected system, giving full control of the host or causing a denial of service.
Attack surface
Reachable over the network via the CIFS browser protocol by sending a crafted BROWSER ELECTION message; the CVSS vector AV:N/AC:L/Au:N indicates no authentication or user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.68, ~99th percentile) and public exploit references exist (Exploit-DB 16166, SecurityFocus BID 46360), indicating known exploit code is available.
What to do
- Apply Microsoft security bulletin MS11-019 for all affected Windows versions.
- Disable the Computer Browser service where it is not required to remove the attack surface.
- Block or restrict NetBIOS/CIFS browser traffic (UDP 138, TCP 139/445) at network boundaries.
- Isolate or retire unsupported legacy systems (XP, Server 2003) that cannot be patched.
- Monitor for anomalous BROWSER ELECTION traffic on internal segments.
Detection
- Monitor network traffic for malformed or unexpected BROWSER ELECTION messages on UDP 138.
- Alert on unexpected system crashes or reboots of Windows hosts running the Computer Browser service.
- Watch for suspicious process creation or privilege escalation following CIFS/browser service activity.
- Review host logs for Mrxsmb.sys or bowser.sys related errors and memory corruption indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0654 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0654), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.