March 3, 2022 · Applied Cybernetics Group
CVE-2011-1889 — Microsoft Forefront Threat Management Gateway (TMG)
Microsoft Forefront TMG Remote Code Execution Vulnerability
- Added to KEV
2022-03-03- Federal due date
2022-03-24- Vendor
- Microsoft
- Product
- Forefront Threat Management Gateway (TMG)
- EPSS
- 99.5th percentile (score 0.881, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2011-1889
CISA short description
A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
Required action
Apply updates per vendor instructions.