← Vulnerability feed

Vulnerability record · CVE-2011-1889 · published 16 June 2011

CVE-2011-1889: Microsoft Forefront TMG client memory corruption allows remote code execution

Microsoft · Forefront Threat Management Gateway

The NSPLookupServiceNext function in the Microsoft Forefront Threat Management Gateway (TMG) 2010 client contains a memory buffer overflow (CWE-119) triggered by unspecified requests. A remote, unauthenticated attacker can corrupt memory and execute arbitrary code, making this a critical pre-auth flaw in an internet-facing security gateway.

9.8 CVSS 3.1 Critical CISA KEV since 3 Mar 2022 EPSS 49% · top 1.2% CWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 10.0
49%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References
16 Jun 2026Last modified by NVD

Description

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, plus confirmed inclusion in CISA KEV, makes this an urgent patch-or-isolate item.

What it is

The NSPLookupServiceNext function in the Microsoft Forefront Threat Management Gateway (TMG) 2010 client contains a memory buffer overflow (CWE-119) triggered by unspecified requests. A remote, unauthenticated attacker can corrupt memory and execute arbitrary code, making this a critical pre-auth flaw in an internet-facing security gateway.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the affected TMG client process, potentially leading to full compromise of the gateway host. Because TMG sits at the network edge, a compromised gateway can expose or disrupt protected internal networks.

Attack surface

Reached over the network via crafted requests to the TMG client, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not specify which requests or ports are involved.

Exploitation

CVE-2011-1889 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild, and EPSS gives a 30-day probability of roughly 0.48 (98.8th percentile). No public exploit details or ransomware association are provided in the record.

What to do

  • Apply the Microsoft security update for MS11-040 (the vendor patch referenced in the record) as the first action.
  • If the affected TMG 2010 client cannot be patched or is end-of-life, isolate or retire it and restrict network exposure of the gateway.
  • Limit which hosts and networks can send requests to the TMG client, using firewall rules and segmentation.
  • Monitor vendor guidance for TMG 2010, which is past end of support, and plan migration to a supported platform.

Detection

  • Monitor for crashes or abnormal termination of the TMG client process, which can indicate memory corruption attempts.
  • Inspect network traffic to the TMG client for malformed or unexpected requests matching the NSPLookupServiceNext code path.
  • Correlate host logs for unexpected child processes or code execution originating from the TMG client process.
  • Alert on exploitation attempts using any available IDS/IPS signatures for MS11-040 or CVE-2011-1889.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2011-1889 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Forefront TMG Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-1889 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.0CVE-2009-0077Microsoft Forefront TMG and ISA Server web listener session state DoSThe firewall engine in Microsoft Forefront Threat Management Gateway Medium Business Edition and ISA Server 2004 SP3, 2006, 2006 Supportability Updat…EPSS 78%analysed4.3CVE-2009-0237Microsoft forefront threat management gateway cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gatewa…EPSS 23%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2011-1889), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.