Vulnerability record · CVE-2011-1889 · published 16 June 2011
CVE-2011-1889: Microsoft Forefront TMG client memory corruption allows remote code execution
Microsoft · Forefront Threat Management Gateway
The NSPLookupServiceNext function in the Microsoft Forefront Threat Management Gateway (TMG) 2010 client contains a memory buffer overflow (CWE-119) triggered by unspecified requests. A remote, unauthenticated attacker can corrupt memory and execute arbitrary code, making this a critical pre-auth flaw in an internet-facing security gateway.
Description
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, plus confirmed inclusion in CISA KEV, makes this an urgent patch-or-isolate item.
What it is
The NSPLookupServiceNext function in the Microsoft Forefront Threat Management Gateway (TMG) 2010 client contains a memory buffer overflow (CWE-119) triggered by unspecified requests. A remote, unauthenticated attacker can corrupt memory and execute arbitrary code, making this a critical pre-auth flaw in an internet-facing security gateway.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the affected TMG client process, potentially leading to full compromise of the gateway host. Because TMG sits at the network edge, a compromised gateway can expose or disrupt protected internal networks.
Attack surface
Reached over the network via crafted requests to the TMG client, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not specify which requests or ports are involved.
Exploitation
CVE-2011-1889 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild, and EPSS gives a 30-day probability of roughly 0.48 (98.8th percentile). No public exploit details or ransomware association are provided in the record.
What to do
- Apply the Microsoft security update for MS11-040 (the vendor patch referenced in the record) as the first action.
- If the affected TMG 2010 client cannot be patched or is end-of-life, isolate or retire it and restrict network exposure of the gateway.
- Limit which hosts and networks can send requests to the TMG client, using firewall rules and segmentation.
- Monitor vendor guidance for TMG 2010, which is past end of support, and plan migration to a supported platform.
Detection
- Monitor for crashes or abnormal termination of the TMG client process, which can indicate memory corruption attempts.
- Inspect network traffic to the TMG client for malformed or unexpected requests matching the NSPLookupServiceNext code path.
- Correlate host logs for unexpected child processes or code execution originating from the TMG client process.
- Alert on exploitation attempts using any available IDS/IPS signatures for MS11-040 or CVE-2011-1889.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2011-1889 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Forefront TMG Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-1889 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-1889), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.