6.9
CVSSv2

CVE-2011-0638

Published: 25/01/2011 Updated: 19/09/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Microsoft Windows does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted malicious users to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows

Github Repositories

BadUSB My presentation will be on CVE-2011-0638, CVE-2011-0639 and CVE-2011-0640 which are all the same vulnerability but one is for windows, one is for Mac OS X and one is for Linux This vulnerability is quite simple, when you connect a USB human interface device (HID) to a computer such as a keyboard/mouse your computer will automatically install the drivers and allow you to