Vulnerability report

High confidence Not in CISA KEV

CVE-2011-4862

FreeBSD

FreeBSD / FreeBSD

Severity
CVSS 10.0 · High
Confidence
High
Exploit status
PoC available
EPSS
95.0%
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2011-4862 is an unauthenticated vulnerability affecting FreeBSD FreeBSD. Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and...

Is it exploited?

Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is high.

Who is affected?

FreeBSD / FreeBSD.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

FreeBSD

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.

View vendor advisory (opens in new tab)
Published
25 Dec 2011
Exploitation Reported
25 Dec 2011
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction

Tags

metasploit

CVE References

  • CVE Record CVE.org · CVE Record https://www.cve.org/CVERecord?id=CVE-2011-4862
  • SUSE-SU-2012:0042 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00010...
  • DSA-2375 debian.org · Vendor Advisory http://www.debian.org/security/2011/dsa-2375
  • RHSA-2011:1854 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1854.html
  • SUSE-SU-2012:0018 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00004...
  • DSA-2372 debian.org · Vendor Advisory http://www.debian.org/security/2011/dsa-2372
  • FEDORA-2011-17493 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2012-Januar...
  • FreeBSD-SA-11:08 security.freebsd.org · Vendor Advisory http://security.freebsd.org/advisories/FreeBSD-SA-11:08.telnetd.asc
  • openSUSE-SU-2012:0019 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00005...
  • FEDORA-2011-17492 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2012-Januar...
  • MDVSA-2011:195 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2011:195
  • SUSE-SU-2012:0024 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00007...
  • SUSE-SU-2012:0050 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00011...
  • RHSA-2011:1852 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1852.html
  • RHSA-2011:1853 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1853.html
  • openSUSE-SU-2012:0051 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00014...
  • SUSE-SU-2012:0010 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00002...
  • SUSE-SU-2012:0056 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00015...
  • RHSA-2011:1851 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-1851.html
  • DSA-2373 debian.org · Vendor Advisory http://www.debian.org/security/2011/dsa-2373
  • 47399 secunia.com · Third-Party Advisory http://secunia.com/advisories/47399
  • 47359 secunia.com · Third-Party Advisory http://secunia.com/advisories/47359
  • 47374 secunia.com · Third-Party Advisory http://secunia.com/advisories/47374
  • 47341 secunia.com · Third-Party Advisory http://secunia.com/advisories/47341
  • 47357 secunia.com · Third-Party Advisory http://secunia.com/advisories/47357
  • 46239 secunia.com · Third-Party Advisory http://secunia.com/advisories/46239
  • 47397 secunia.com · Third-Party Advisory http://secunia.com/advisories/47397
  • 47373 secunia.com · Third-Party Advisory http://secunia.com/advisories/47373
  • 47441 secunia.com · Third-Party Advisory http://secunia.com/advisories/47441
  • 47348 secunia.com · Third-Party Advisory http://secunia.com/advisories/47348
  • 18280 exploit-db.com · Exploit http://www.exploit-db.com/exploits/18280/
  • 78020 osvdb.org · VDB Entry http://osvdb.org/78020
  • 1026463 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1026463
  • 1026460 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1026460
  • multiple-telnetd-bo(71970) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/71970
  • 20111226 MITKRB5-SA-2011-008 buffer overflow in telnetd [CVE-2011-4862] archives.neohapsis.com · Mailing List http://archives.neohapsis.com/archives/bugtraq/2011-12/0172.html
  • [freebsd-security] 20111223 Merry Christmas from the FreeBSD Security Team lists.freebsd.org · Mailing List http://lists.freebsd.org/pipermail/freebsd-security/2011-December/006...
  • [freebsd-security] 20111223 Merry Christmas from the FreeBSD Security Team lists.freebsd.org · Mailing List http://lists.freebsd.org/pipermail/freebsd-security/2011-December/006...
  • [freebsd-security] 20111223 Merry Christmas from the FreeBSD Security Team lists.freebsd.org · Mailing List http://lists.freebsd.org/pipermail/freebsd-security/2011-December/006...
  • [freebsd-security] 20111223 Merry Christmas from the FreeBSD Security Team lists.freebsd.org · Mailing List http://lists.freebsd.org/pipermail/freebsd-security/2011-December/006...
  • security.freebsd.org/patches/SA-11:08/telnetd.patch security.freebsd.org · CVE Record http://security.freebsd.org/patches/SA-11:08/telnetd.patch
  • git.savannah.gnu.org/cgit/inetutils.git/commit git.savannah.gnu.org · CVE Record http://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=665f1e73cdd...
  • web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2011-008.txt web.mit.edu · CVE Record http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2011-008.txt

Exploitation evidence

Why KEV Intelligence marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Proof of concept available

GitHub

Recorded 02 Feb 2017

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.

Learn about Pro API access
Source Added
CVE First 2011-12-25 01:00 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
0
User-Agents
0

Raw values available in Pro and Enterprise.

Virtual patch status

No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

Scanner Artifacts

Scanner and exploit-framework references linked to this CVE.

Risk and context

Severity, weaknesses, and research context

CVSS v2.0

10.0 High
AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

95.0%

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

telnet_encrypt_keyid

metasploit · Created Unknown

Metasploit module for CVE-2011-4862

telnet_encrypt_keyid

metasploit · Created Unknown

Metasploit module for CVE-2011-4862

Timeline

From disclosure to observed exploitation

  1. Metasploit module available

    Exploit module available

  2. Public PoC available

    Public proof-of-concept code published

  3. Added to KEV Intelligence KEV Feed

    High-confidence, third-party attested exploitation

  4. CVE published

    Vulnerability disclosed publicly

  5. CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2011-4862

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2011-4862",
  "confidence": "High",
  "cvss_score": 10.0,
  "cvss_estimated": false,
  "epss_score": 0.94983,
  "exploit_status": {
    "exploited_in_the_wild": false,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.