« Back to list

Microsoft

Microsoft Host Integration Server: vulnerabilities and CVEs

Microsoft Host Integration Server has 4 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical0
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2012-1856High (8.8)72%⚠ Active exploitationAug 15, 2012
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-38151High (8.8)1.8%—Nov 14, 2023
Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability
CVE-2012-1856High (8.8)72%⚠ Active exploitationAug 15, 2012
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL…
CVE-2011-2008Medium (5)21%—Oct 12, 2011
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated…
CVE-2011-2007Medium (5)23%—Oct 12, 2011
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft